Laserfiche WebLink
2.12 Gehring Group shall, upon written request from Client, make any amendment to PHI in a <br />Designated Record Set maintained by Gehring Group within thirty (30) days of receipt of <br />the request unless Gehring Group can establish to Client's satisfaction that the PHI at <br />issue is accurate and complete. <br />2.13 If an Individual's PHI is held in an Electronic Health Record, Gehring Group shall <br />provide requested copies in electronic format to the individual or to an entity or person <br />designated by the Individual, provided such designation is clearly and conspicuously <br />made by the Individual or Client. <br />2.14 Gehring Group shall make its internal practices, written policies and procedures, books, <br />records, and other documents relating to the use and disclosure of PHI and/or Electronic <br />PHI created or maintained by Gehring Group on behalf of Client available to the <br />Secretary of the Department of Health and Human Services, or his or her designee, for <br />purposes of the Secretary determining Client's compliance with HIPAA. <br />2.15 Gehring Group shall make available the information required to provide an accounting of <br />disclosures made on and after the Effective Date, as necessary for Client to comply with <br />45 C.F.R. § 164.528, within twenty (20) business days of receipt of the request. Gehring <br />Group shall provide one such accounting within a twelve month period without charge, <br />but may make a reasonable charge for any additional such accountings within the same <br />twelve month period. <br />2.16 Gehring Group shall maintain all records, other than those records that are also <br />maintained by Client, for six (6) years from the date created or last in effect, whichever is <br />later, as necessary for Client to comply with 45 C.F.R. § 164.530(j)(2). <br />3. PERMITTED USES OF PHI <br />3.1 Gehring Group may use and disclose PHI and Electronic PHI as necessary to provide <br />services to Client, subject to Section 2.3 of this Agreement and consistent with the <br />requirements of HIPAA. <br />3.2 Gehring Group may use and disclose PHI and Electronic PHI as necessary for the proper <br />management and administration of Gehring Group or to carry out Gehring Group's legal <br />responsibilities, subject to Section 2.4 of this Agreement and consistent with the <br />requirements of HIPAA; provided, however, that Gehring Group may disclose the PHI <br />and Electronic PHI for such purposes only if: <br />i. the disclosure is Required by Law, or <br />ii. Gehring Group obtains reasonable assurances that the party to whom the PHI or <br />Electronic PHI is disclosed (a) will protect the confidentiality of the PHI and <br />Electronic PHI, (b) will not further disclose the PHI or Electronic PHI except as <br />Required by Law or for the purposes for which it was disclosed to the other party, <br />and (c) will report any improper use or disclosure of the PHI and/or Electronic <br />PHI to Gehring Group. <br />Page 5 of 8 <br />17535410v 1 <br />