Laserfiche WebLink
A TRUE COPY <br />CERTIFICATION ON LAST PAGE <br />RYAN L. BUTLER, CLERK <br />9. Make its internal practices, books, and records relating to its use and disclosure of <br />Protected Health Information available to the Plan and to DHHS to determine the <br />Plan's compliance with 45 C.F.R. Part 164, Subpart E "Privacy of Individually <br />Identifiable Health Information." <br />10. Return to the Plan or destroy if feasible all Protected Health Information in <br />whatever form or medium that Employer (and any subcontractor or agent of <br />Employer) received from the Plan or BCBSF, including all copies thereof and all <br />data, compilations, and other works derived there from that allow identification of <br />any present or past Member who is the subject of Protected Health Information, <br />when Employer no longer needs Protected Health Information for the plan <br />administration functions for which the Employer received Protected Health <br />Information. Employer will limit the use or disclosure of any of Protected Health <br />Information that Employer (or any subcontractor or agent of Employer) cannot <br />feasibly return to the Plan or destroy to the purposes that make its return to the <br />Plan or destruction infeasible. <br />PART 2 - Employer to Amend Plan Documents for Security Provisions <br />Employer further certifies that Employer has amended the Plan's Plan Document to <br />incorporate the provisions required by 45 C.F.R. § 164.314(b)(2), as set forth below, and <br />agrees to comply with the Plan's Plan Document as amended. <br />1. Implement administrative, physical, and technical safeguards that reasonably and <br />appropriately protect the confidentiality, integrity, and availability of Electronic <br />Protected Health Information that Employer creates, receives, maintains or <br />transmits on the Plan's behalf. <br />2. Ensure that the adequate separation between Employer and the Plan required by <br />45 C.F.R. § 164.504(f)(2)(iii) (as described in item 3 above) is supported by <br />reasonable and appropriate Security Measures. <br />3. Ensure that any subcontractor or agent to which Employer provides Electronic <br />Protected Health Information agrees to implement reasonable and appropriate <br />Security Measures to protect the Electronic Protected Health Information. <br />4. Report to the Plan any incident of which Employer becomes aware that is (a) a <br />successful unauthorized access, use or disclosure of Electronic Protected Health <br />Information; or (b) a successful major (i) modification or destruction of Electronic <br />Protected Health Information or (ii) interference with system operations in an <br />Information System containing or having access to Electronic Protected Health <br />Information. Upon the Plan's request, Employer will report any incident of which <br />Employer becomes aware that is a successful minor (a) modification or destruction <br />of Electronic Protected Health Information or (b) interference with system <br />operations in an Information System containing or having access to Electronic <br />Protected Health Information. <br />24 <br />