Orange County NC Website
I~ <br />Consolidated Agreement- Final <br />Page 16 of 19 <br />NORTH CAROLINA <br />DEPARTMENT OF HEALTH AND HUMAN SERVICES <br />BUSINESS ASSOCIATE ADDENDUM TO MEMORANDUM OF UNDERSTANDING <br />This Agreement is made effective the 1st day of July, 2008, by and between <br />(name of Local Health Department or "Covered Entity") and the Division of Public Health ("Business Associate") <br />(collectively the "Parties"). <br />1. BACKGROUND <br />a. Covered Entity and Business Associate are parties to a Memorandum of Understanding "entitled" The FY2009 <br />Consolidated Agreement (the "MOU"), whereby Business Associate agrees to perform certain services for or <br />on behalf of Covered Entity. . <br />b. Covered Entity is an organizational unit of the North Carolina Department of Health and Human Services (the <br />"Department") that has been designated in whole or in part by the Department as a health care component for <br />purposes of the HIPAA Privacy and Security Rules. <br />c. The relationship between Covered Entity and Business Associate is such that the Parties believe Business <br />Associate is or may be a "business associate" within the meaning of the HII'AA Privacy and Security Rules. <br />d. The Parties enter into this Business Associate Addendum to the MOU with the intention of complying with the <br />HIPAA Privacy and Security Rules provision that a covered entity may disclose electronic protected health <br />information or other protected health information to a business associate, and may allow a business associate to <br />create or receive electronic protected health information or other protected heath information on its behalf, if the <br />covered entity obtains satisfactory assurances that the business associate will appropriately safeguard the <br />information. - <br />2. DEFINITIONS. <br />Unless some other meaning is clearly indicated by the context, the following terms shall have the following meaning in <br />this Agreement: <br />a. "Electronic Protected Health Information" shall have the same meaning as the term "electronic protected health <br />information" in 45 CFR 160.103, limited to the information created or received by Business Associate from or <br />on behalf of a Covered Entity. <br />b. "HIPAA" means the Administrative Simplescation Provisions, Sections 261 through 264, of the federal Health <br />Insurance Portability and Accountability Act of 1996, Public Law 104-191. <br />c. "Individual" shall have the same meaning as the term "individual" in 45 CFR 160.103 and shall include a person <br />who qualifies as a personal representative in accordance with 45 CFR 164.502(8). <br />d. "Privacy and Security Rules" shall mean the Standards for Privacy of Individually Identifiable Health <br />Information and Security Standards for the Protection of Electronic Protected Health Information in accordance <br />with 45 CFR part 160 and part 164, subparts A and E. <br />e. "Protected Health Information" shall have the same meaning as the term "protected health information" in 45 <br />CFR 160.103, limited to the information created or received by Business Associate from or on behalf of Covered <br />Entity. <br />f. "Required By Law" shall have the same meaning as the term "required by law" in 45 CFR 164.103. <br />g. "Secretary" shall mean the Secretary of the United States Department of Health and Human Services or his <br />designee. <br />