Page 5 of 7
PAI (03/21)
HIPAA Business Associate Agreement
This Agreement is made between METROPOLITAN LIFE INSURANCE COMPANY and its affiliates
(“MetLife”), and the party identified below as the producer (“Producer”).
WHEREAS, MetLife and Producer have one or more agreements in place (collectively, the “Contract”)
whereby Producer agreed to provide certain services for MetLife which may involve the use and/or disclosure of
Customer Information and Protected Health Information (“PHI”) as defined below, and whereby Producer may
have access to certain information about individuals who have applied for or are covered by an insurance
product underwritten by MetLife; and
WHEREAS, MetLife and Producer desire to protect the confidentiality of any Customer Information or PHI
disclosed to Producer pursuant to the Contract and to satisfy requirements of the Health Insurance Portability
and Accountability Act of 1996 (“HIPAA”) and as amended by the Health Information Technology for Economic
and Clinical Health Act ("HITECH Act"),
NOW, THEREFORE, MetLife and Producer hereby agree as follows:
1.
Capitalized terms not defined herein that are defined in the Contract shall have the meanings ascribed to
them in the Contract.
2.
Producer agrees to treat all information about individuals who enroll, apply for or purchase MetLife’s products
or services that Producer may have or may obtain in connection with its obligations under the Contract
(“Customer Information”) as confidential. Customer Information may include, but is not limited to, an
individual’s name, address, social security number, and any financial or health information relating to the
individual. Producer may use Customer Information only for the purpose of fulfilling its obligations under the
Contract and Producer may not disclose Customer Information to anyone other than the individual to whom
the information relates, except as required for Producer to fulfill its obligations under the Contract or as
otherwise directed by MetLife, or except as expressly required by law. Producer must also ensure that
Customer Information is kept in a secure manner.
3.
PHI is defined as individually identifiable information that is transmitted or maintained in any medium and
relates to: the past, present or future physical or mental health or condition of an individual; the provision of
health care to an individual; or past, present, or future payment for the provision of health care to the
individual. MetLife and Producer understand that this definition of PHI includes demographic information
about the individual, including names; geographic subdivisions smaller than a state (including but not
limited to street addresses and ZIP codes); all elements of dates (except year) for dates directly related to an
individual, including but not limited to birth date; telephone numbers; fax numbers; electronic mail (E-mail)
addresses; Social Security numbers;Medical record numbers; health plan beneficiary numbers; account
numbers; certificate/license numbers; vehicle identifiers and serial numbers, including license plate numbers;
device identifiers and serial numbers;Web Universal Resource Locators (URLs); Internet Protocol (IP)
address numbers; biometric identifiers, including finger and voice prints; full face photographic images and
any comparable images; and any other unique identifying number, characteristic, or code.
4.
In order to further protect the confidentiality of any PHI disclosed to or used by Producer pursuant to the
Contract and to satisfy requirements of HIPAA, MetLife and Producer agree to the following with respect to
any PHI received or created by Producer in providing services pursuant to the Contract, including PHI
received or created prior to the effective date of the Contract (“MetLife PHI”): (a) the obligations regarding
MetLife PHI contained in this Agreement shall be in addition to any other obligations contained in the
Contract that apply to MetLife PHI; (b) Producer may not use or disclose MetLife PHI except to provide
services pursuant to the Contract; (c) Producer shall use appropriate safeguards to prevent use or disclosure
of MetLife PHI; (d) MetLife and Producer represent and warrant that their security procedures are adequate
to protect and maintain the confidentiality of MetLife PHI; (e) Producer shall promptly report to MetLife any
use or disclosure of MetLife PHI not permitted by this Agreement of which it becomes aware; (f) Producer
shall ensure that any Agents, including any sub-contractors or Producer affiliates, that Producer may use in
accordance with the Contract and to whom Producer provides MetLife PHI or who uses MetLife PHI has
been approved by MetLife in writing and agrees to the same restrictions and conditions that apply to
Producer with respect to MetLife PHI pursuant to this Agreement; (g) within thirty (30) days of MetLife’s
request, Producer shall provide to MetLife any MetLife PHI or information relating to MetLife PHI as deemed
necessary by MetLife to comply with its obligations under HIPAA to provide individuals with access to,
amendment of, and an accounting of disclosures of their MetLife PHI, and Producer agrees to incorporate
any amendments of the MetLife PHI as requested by MetLife; (h) Producer agrees to make its internal