Laserfiche WebLink
( 2 ) In the event that any member of the Employer's workforce uses or <br /> discloses Protected Health Information other than as permitted by this <br /> Section and the Privacy Standards , the incident shall be reported to the <br /> Plan ' s privacy officer. The privacy officer shall take appropriate action , <br /> including : <br /> ( i ) investigation of the incident to determine whether the <br /> breach occurred inadvertently, through negligence or deliberately; <br /> whether there is a pattern of breaches ; and the degree of harm <br /> caused by the breach ; <br /> ( ii ) appropriate sanctions against the persons causing the <br /> breach which , depending upon the nature of the breach , may <br /> include oral or written reprimand , additional training , or termination <br /> of employment; <br /> ( iii ) mitigation of any harm caused by the breach , to the <br /> extent practicable ; and <br /> ( iv) documentation of the incident and all actions taken to <br /> resolve the issue and mitigate any damages . <br /> (e ) The Employer must provide certification to the Plan that it agrees <br /> to : <br /> ( 1 ) Not use or further disclose the information other than as permitted <br /> or required by the Plan documents or as required by law ; <br /> ( 2 ) Ensure that any agent or subcontractor, to whom it provides <br /> Protected Health Information received from the Plan , agrees to the same <br /> restrictions and conditions that apply to the Employer with respect to such <br /> information ; <br /> ( 3 ) Not use or disclose Protected Health Information for employment- <br /> related actions and decisions or in connection with any other benefit or <br /> employee benefit plan of the Employer; <br /> ( 4 ) Report to the Plan any use or disclosure of the Protected Health <br /> Information of which it becomes aware that is inconsistent with the uses <br /> or disclosures permitted by this Section , or required by law; <br /> ( 5 ) Make available Protected Health Information to individual Plan <br /> members in accordance with Section 164 . 524 of the Privacy Standards ; <br /> ( 6 ) Make available Protected Health Information for amendment by <br /> individual Plan members and incorporate any amendments to Protected <br /> Health Information in accordance with Section 164 . 526 of the Privacy <br /> Standards ; <br /> ( 7 ) Make available the Protected Health Information required to <br /> provide an accounting of disclosures to individual Plan members in <br /> accordance with Section 164 . 528 of the Privacy Standards ; <br /> ( 8 ) Make its internal practices , books and records relating to the use <br /> and disclosure of Protected Health Information received from the Plan <br /> 26 <br />