Page 4 of 9
3. Safeguards Against Misuse of PHI. Business Associate will use appropriate safeguards to
prevent the use or disclosure of PHI other than as provided by the Agreement or this BAA and Business
Associate agrees to implement administrative, physical, and technical safeguards that reasonably and
appropriately protect the confidentiality, integrity and availability of the Electronic PHI that it creates,
receives, maintains or transmits on behalf of Covered Entity. Business Associate agrees to take
reasonable steps, including providing adequate training to its employees to ensure compliance with this
BAA and to ensure that the actions or omissions of its employees or agents do not cause Business
Associate to breach the terms of this BAA.
4. Reporting Disclosures of PHI and Security Incidents. Business Associate will report to Covered
Entity in writing any use or disclosure of PHI not provided for by this BAA of which it becomes aware and
Business Associate agrees to report to Covered Entity any Security Incident affecting Electronic PHI of
Covered Entity of which it becomes aware. Business Associate agrees to report any such event within
five business days of becoming aware of the event.
5. Reporting Breaches of Unsecured PHI. Business Associate will notify Covered Entity in writing
promptly upon the discovery of any Breach of Unsecured PHI in accordance with the requirements set
forth in 45 CFR §164.410, but in no case later than 30 calendar days after discovery of a Breach. Business
Associate will reimburse Covered Entity for any costs incurred by it in complying with the requirements
of Subpart D of 45 CFR §164 that are imposed on Covered Entity as a result of a Breach committed by
Business Associate.
6. Mitigation of Disclosures of PHI. Business Associate will take reasonable measures to mitigate,
to the extent practicable, any harmful effect that is known to Business Associate of any use or disclosure
of PHI by Business Associate or its agents or subcontractors in violation of the requirements of this BAA.
7. Agreements with Agents or Subcontractors. Business Associate will ensure that any of its
agents or subcontractors that have access to, or to which Business Associate provides, PHI agree in
writing to the restrictions and conditions concerning uses and disclosures of PHI contained in this BAA
and agree to implement reasonable and appropriate safeguards to protect any Electronic PHI that it
creates, receives, maintains or transmits on behalf of Business Associate or, through the Business
Associate, Covered Entity. Business Associate shall notify Covered Entity, or upstream Business
Associate, of all subcontracts and agreements relating to the Agreement, where the subcontractor or
agent receives PHI as described in section 1.M. of this BAA. Such notification shall occur within 30
(thirty) calendar days of the execution of the subcontract by placement of such notice on the Business
Associate’s primary website. Business Associate shall ensure that all subcontracts and agreements
provide the same level of privacy and security as this BAA.
8. Audit Report. Upon request, Business Associate will provide Covered Entity, or upstream
Business Associate, with a copy of its most recent independent HIPAA compliance report (AT-C 315),
HITRUST certification or other mutually agreed upon independent standards based third party audit
report. Covered entity agrees not to re-disclose Business Associate’s audit report.
9. Access to PHI by Individuals.
A. Upon request, Business Associate agrees to furnish Covered Entity with copies of the
PHI maintained by Business Associate in a Designated Record Set in the time and manner