Orange County NC Website
15 <br /> (iii) implement appropriate safeguards to prevent use or disclosure of <br /> protected health information other than as permitted or required by this <br /> Agreement; <br /> (iv) permit the Secretary of Health and Human Services to audit <br /> Business Associate's records and practices related to use and disclosure of <br /> protected health information to ensure Covered Entity's compliance with the <br /> terms of the HIPAA Privacy Rule; <br /> (v) report to Covered Entity any use or disclosure of protected health <br /> information which is not in compliance with the terms of this Agreement of which <br /> it becomes aware; and <br /> (vi) mitigate, to the extent practicable, any harmful effect that is <br /> known to Business Associate of a use or disclosure of protected health information <br /> by Business Associate in violation of the requirements of this Agreement. <br /> (b) Notwithstanding the prohibitions set forth in this Agreement or the Arrangement <br /> Agreement,-Business Associate may use and disclose protected health <br /> information as follows: <br /> (i) if necessary, for the proper management and administration of <br /> Business Associate or to carry out the legal responsibilities of Business Associate, <br /> provided that as to any such disclosure, the following requirements are met: <br /> (A) the disclosure is required by law; or <br /> (B) Business Associate obtains reasonable assurances from the <br /> person to whom the information is disclosed that it-will be held <br /> confidentially and used or further disclosed only as required by law or for <br /> the purpose for which it was disclosed to the person, and the person <br /> notifies Business Associate of any instances of which it is aware in which <br /> the confidentiality of the information has been breached: <br /> (ii) for data aggregation services, if such services are to be provided <br /> by Business Associate for the health care operations of Covered Entity pursuant to <br /> any agreements between the Parties evidencing their business relationship. <br /> Ill. AVAILABILITY OF PROTECTED HEALTH INFORMATION <br /> Business Associate shall: <br /> (a) at the request of Covered Entity, provide access to protected health information <br /> in a designated record set to Covered Entity or, as directed by Covered Entity, to <br /> an individual, in a time and manner sufficient to permit Covered Entity to comply <br /> with the requirements of 45 CFR 164.524. <br /> (b) at the request of Covered Entity or an individual, make any amendment(s) to <br /> protected health information in a designated record set that are directed by or <br /> agreed to by Covered Entity, in a time and manner sufficient to permit Covered <br /> Entity to comply with the requirements of 45 CFR 164.526. <br /> (c) document disclosures of protected health information and information related to <br /> such disclosures in a manner sufficient to permit Covered Entity to respond to a <br /> request by an individual for an accounting of disclosures of protected health <br /> information in accordance with 45 CFR 164.528 and provide such documentation <br /> to Covered Entity or an individual as directed by Covered Entity. <br />