Orange County NC Website
aA F"40if�/1. <br /> 1 . 4 . " Protected Health Information " or " PHI " shall have the same meaning as the term <br /> " protected health information " at 45 C . F . R . § 160 . 103 , limited to the information created or received by <br /> BA from or on behalf of Covered Entity . PHI shall include Electronic Protected Health Information . <br /> Notwithstanding anything to the contrary in this Addendum , the term " PHI " as used in this Addendum <br /> shall not include any information that BA would otherwise be able to receive as a HIPAA covered entity <br /> in the patient ' s continuum of care . <br /> 1 . 5 . " Secretary" shall mean the Secretary of the United States Department of Health and <br /> Human Services or his or her designee . <br /> 1 . 6 . " Security Incident " shall have the same meaning as the term " security incident " at 45 <br /> C . F . R . § 164 . 304 . <br /> 1 . 7 . " Unsecured PHI " shall have the same meaning as the term " unsecured protected health <br /> information " at 45 C . F . R . § 164 . 402 . <br /> 2 . BA Obligations . The parties agree that BA shall . <br /> 2 . 1 . Not use or disclose PHI other than as permitted by this Addendum , the Underlying <br /> Agreement , the Privacy Rule , or as Required By Law ; <br /> 2 . 2 . Use appropriate safeguards to prevent the use or disclosure of PHI other than as <br /> provided for by this Addendum . BA shall implement administrative , physical , and technical safeguards <br /> that reasonably and appropriately protect the confidentiality , integrity and availability of Electronic PHI <br /> that it creates , receives , maintains , or transmits on behalf of Covered Entity . BA shall comply with the <br /> applicable requirements of Subpart C of Part 164 of the Security Rules <br /> 2038 Limit any uses , disclosures , and requests for PHI to the minimum amount necessary to <br /> perform or fulfill a specific function required or permitted by this Addendum in accordance with the <br /> HIPAA Rules ; <br /> 2 . 4 . Mitigate to the extent practicable , any harmful effect that is known to BA from a use or <br /> disclosure of PHI by BA in violation of this Addendum ; <br /> 2 . 5 . Timely report to Covered Entity any use or disclosure of PHI of which BA becomes aware <br /> that is not provided for or allowed by this Addendum or the HIPAA Rules , including Breaches of <br /> Unsecured PHI that BA discovers as required by, and in the manner set forth at , 45 C . F . R . § 164 . 410 , and <br /> any Security Incident of which BA becomes aware . The parties acknowledge and agree that this section <br /> constitutes notice by BA to Covered Entity of the ongoing existence and occurrence of attempted but <br /> Unsuccessful Security Incidents ( as defined below ) for which no additional notice to Covered Entity shall <br /> be required . " Unsuccessful Security Incidents " shall include , but are not limited to , pings and other <br /> broadcast attacks on BA ' s firewall , port scans , unsuccessful log - on attempts , denials of service and any <br /> combination of the above , so long as no such incident results in unauthorized acquisition , access , use , or <br /> disclosure of PHI , <br /> 2 . 6 . In accordance with 45 C . F . R . § § 164 . 308 ( b ) ( 2 ) and 164 . 502 ( e ) ( 1 ) ( ii ) , require any of its <br /> agents or subcontractors that maintain , create , receive , and / or transmit PHI on behalf of BA to agree , in <br /> 21 of 24 <br /> MAT- 63397 OrangeCountyHD - WAG 340E 10312019 ( be ) V1 . 0 © 2019 Walgreen Co . All rights reserved . <br />