Laserfiche WebLink
received from, or created or received by the Business Associate on behalf of the Company, then the <br />Business Associate will enter into an agreement with such agent or subcontractor whereby the agent or <br />subcontractor agrees to be bound by the terms of this Agreement with respect to PHI. <br />4. Safeguards for Protection of PHI, Report of Unauthorized Use or Disclosure. The <br />Business Associate agrees that it will implement and use appropriate safeguards to prevent any Use or <br />Disclosure of PHI in violation of this Agreement. The Business Associate agrees that it will report to the <br />Company any Use or Disclosure of PHI, of which the Business Associate becomes aware, that is in <br />violation of this Agreement. The Business Associate agrees to mitigate, to the extent practicable, any <br />harmful effect that is known to the Business Associate of a Use or Disclosure of PHI by the Business <br />Associate in violation of this Agreement. <br />5. Cooperation by the Business Associate. The Business Associate agrees to cooperate <br />with the Company in providing an accounting of Disclosures of PHI received under this Agreement as <br />requested by an individual to whom it relates, except to the extent the Regulations provide otherwise. In <br />the event that Business Associate uses or maintains an electronic health record, Business Associate agrees <br />that such accounting shall include disclosures made to carry out treatment, payment, and health care <br />operations through the use of such electronic health record. Upon receiving a request for an accounting of <br />disclosures directly from an individual who has received an accounting of disclosures from Company, <br />which provided a list of all business associates acting on behalf of the Plan, including Business Associate, <br />Business Associate agrees to provide an accounting of its disclosures of PHI to such individual as <br />required by the Privacy Regulations. In response to such a request from an individual, Business <br />Associate may elect to provide either (i) an accounting of disclosures that includes disclosures of <br />subcontractors and/or agents acting on behalf of Business Associate or (ii) an accounting of disclosures <br />that are made by the Business Associate as well as a list of all subcontractors and/or agents acting on <br />behalf of Business Associate, including contact information such as mailing address, phone, and email <br />address. The Business Associate shall respond to requests from the Company for the information <br />described in this Section 5 and make available such information to the Company within a reasonable <br />period of time to enable the Company to timely respond to any request. <br />The Company agrees that the Business Associate will not maintain any Designated Record Sets <br />on its behalf and that the Business Associate assumes no responsibility to respond to individuals' requests <br />for access or amendments as provided in Sections 164.524 and 164.526 of the Regulations. <br />Business Associate agrees that the requirements of the Privacy Regulations shall be applicable to <br />Business Associate in the performance of its obligations pursuant to the Agreement. <br />Business Associate agrees that it shall not directly or indirectly receive remuneration in exchange <br />for any PHI, unless a valid authorization, as that term is defined at 45 C.F.R. § 164.508, is obtained or the <br />purpose of the exchange meets one of the exceptions set forth in set forth in the 45 C.F.R. <br />164.502(a)(5)(ii). <br />6. Documenting Disclosures. In order to cooperate with the Company in accordance with <br />Section 5 above, the Business Associate agrees to document all Disclosures of PHI and information <br />related to such Disclosures as would be required for the Company to respond to an individual's request <br />for an accounting of Disclosures of PHI under Section 164.528 of the Regulations. Such documentation <br />shall include: (a) the date of the Disclosure; (b) the name of the entity or person who received the PHI <br />and, if known, the address of such entity or person; (c) a brief description of the PHI Disclosed; and (d) a <br />brief statement of the purpose of the Disclosure (which would reasonably inform an individual of the <br />basis for the Disclosure). <br />NOT FOR DISTRIBUTION. THE INFORMATION CONTAINED HEREIN IS CONFIDENTIAL, PROPRIETARY <br />AND CONSTITUTES TRADE SECRETS OF ESI AND RXBENEFITS <br />34 <br />