Orange County NC Website
11 <br />Exhibit A <br /> <br />BUSINESS ASSOCIATE AGREEMENT <br /> <br /> <br /> <br />This Business Associate Agreement (“Agreement”) is by and between Orange County Asset Management <br />(“Covered Entity“) and Starpoint Global Services (“Business Associate”). <br /> <br /> <br />RECITALS <br /> <br /> WHEREAS, Covered Entity has engaged Business Associate to perform services or provide goods, or both; <br /> <br /> WHEREAS, Covered Entity possesses Individually Identifiable Health Information that is protected under <br />HIPAA and the HIPAA Regulations, and is permitted to use or disclose such information only in accordance with <br />HIPAA and the HIPAA Regulations; <br /> <br /> WHEREAS, Business Associate may receive such information from Covered Entity, or create and receive <br />such information on behalf of Covered Entity, in order to perform certain of the services or provide certain of the <br />goods, or both; and <br /> <br /> WHEREAS, Covered Entity wishes to ensure that Business Associate will appropriately safeguard <br />Individual Identifiably Health Information; <br /> <br /> NOW THEREFORE, Covered Entity and Business Associate agree as follows: <br /> <br />1. Definitions. The parties agree that the following terms, when used in this Agreement, shall have the <br />following meanings, provided that the terms set forth below shall be deemed to be modified to reflect any changes <br />made to such terms from time to time as defined in HIPAA and the HIPAA Regulations. <br /> <br />a. “HIPAA” means the Health Insurance Portability and Accountability Act of 1996, Public Law <br />104-191. <br /> <br />b. “HIPAA Regulations” means the regulations promulgated under HIPAA by the United States <br />Department of Health and Human Services, including, but not limited to, 45 C.F.R. Part 160 and 45 C.F.R. <br />Part 164 subparts A and E (“The Privacy Rule”) and the Security Standards as they may be amended from <br />time to time, 45 C.F.R. Parts 160, 162 and 164, Subpart C (“The Security Rule”). <br /> <br />c. “Business Associate” means, with respect to a Covered Entity, a person who: <br /> <br />(1) on behalf of such Covered Entity or of an organized health care arrangement (as defined <br />under the HIPAA Regulations) in which the Covered Entity participates, but other than in the <br />capacity of a member of the workplace of such Covered Entity or arrangement, performs, or <br />assists in the performance of: <br /> <br />a) a function or activity involving the use or disclosure of Individually Identifiable <br />Health Information, including claims processing or administration, data analysis, <br />processing or administration, utilization review, quality assurance, billing, benefit <br />management, practice management, and repricing; or <br /> <br />b) any other function or activity regulated by the HIPAA Regulations; or <br /> <br />(2) provides, other than in the capacity of a member of the workforce of such Covered <br />Entity, legal, actuarial, accounting, consulting, Data Aggregation, management, administrative, <br />DocuSign Envelope ID: 2A625151-A0A5-4550-AF52-91CBC3DDBC3C