University Policies

Page tree

Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...


ROWAN

...

UNIVERSITY POLICY



Title:

...

Disclosures of Personally Identifiable Health Information to Business Associates
Subject:

...

Office of Compliance & Corporate Integrity (OCCI)
Policy No:

...

OCCI:2013:P08
Applies:

...

Rowan-Virtua SOM
Issuing Authority:

...

Chief Audit, Compliance & Privacy Officer; Chief Information Security Officer
Responsible Officer: Chief Audit, Compliance & Privacy Officer; Chief Information Security Officer
Adopted:

...

 07/01/2013
Last Revision: 05/01/2026
Last Reviewed: 05/01/2026

I.   

...

PURPOSE

To assure compliance with the requirements of the Health Insurance Portability and Accountability Act (HIPAA) of 2004, Health Information Technology for Economic and Clinical Health (HITECH) Act of 2009 and the Omnibus Privacy Final Rule of 2013 in relation to disclosures of Protected Health Information (PHI) and to entering into contracts with business associates.

II. 

...

 ACCOUNTABILITY

Under the direction of the President, the Deans,

...

Chancellors, Chief Audit, Compliance & Privacy Officer, Vice President for Finance and

...

Treasurer and General Counsel shall ensure compliance with this policy.

III. 

...

APPLICABILITY

This policy shall apply to disclosures to business associates of health information that is generated during provisions of health care to patients in any of the

...

Rowan-Virtua SOM’s patient care units, patient care centers of faculty practices as well as Human Subjects research under the auspices of

...

Rowan-Virtua SOM or by any of its agents in all

...

Rowan-Virtua SOM, Units, Departments and University owned or operated facilities.

IV. 

...

DEFINITIONS

...

  1. "Protected Health Information (PHI)" - Protected health information means individually identifiable health information that relates to the past, present or future physical or mental health or condition of an individual, the provision of health care to an individual or the past, present or future payment for the provision of health care to an individual and identifies or could reasonably be used to identify the individual. PHI of a decedent, who has been deceased for more than 50 years, is no longer considered protected PHI [160.103 and 164.502(f)].
    1. Except as provided in paragraph two (2) of this definition that is: a) transmitted
    by electronic
    1. by electronic media; b) maintained in electronic media; or c) transmitted or maintained
    in any
    1. in any other form or medium.
    2. Protected health information excludes individually identifiable health information in: a)
    Education
    1.  Education records covered by the Family Educational Rights and Privacy Act,
    as amended
    1. as amended, 20 U.S.C. 1232g; b) Records described at 20 U.S.C. 1232g(a)(4)(B)(iv); and c)
    Employment
    1.  Employment records held by a covered entity in its role as employer.

...

  1. Business Associates (BA)

...

  1. – Entity that

...

  1. “creates, receives, maintains, or

...

  1. transmits” PHI on

...

  1. behalf of the CE [Patient Safety and Quality Improvement Act (PSQIA) of 2005, 42 U.S.C. 299b-22,

...

  1. et seq.]. The BA now has direct liability for compliance with this rule (164.500),

...

  1. including implementing and operating Minimum Necessary [164.502(b)]. A Subcontractor is a person,

...

  1. who the BA has delegated a function, activity or services that the BA has agreed to perform on

...

  1. behalf of the CE (160.103). Subcontractors must also comply with the privacy and security rules

...

  1. under the BA Agreement [164.504(e)(4)(ii)(B)]. The CE and BA are obligated to assess, administer

...

  1. and monitor of the organizations

...

  1. “downstream” from the CE that manage PHI. The BA is required

...

  1. to enter into a BA Agreement (BAA) with the subcontractor, not the CE and subcontractor.

...

  1. person other than in the capacity of a member of the workforce that on behalf of

...

  1. Rowan-Virtua SOM, its units,

...

  1.  or any organized health care arrangement in which it participates, performs or assists in

...

  1. the performance of:
    1. a function or activity involving the use or disclosure of individually identifiable
    health information
    1. health information, including claims processing or administration, data analysis, processing
    or administration
    1. or administration, utilization review, quality assurance, billing, benefit management,
    practice
    1.  practice management and re-pricing; or
    2. any other function or activity regulated by HIPAA regulations; or
    3. provides legal, actuarial, accounting, auditing, consulting, data aggregation (as defined
    in CFR
    1. in CFR § 164.501), management, administrative, accreditation, or financial services to
    or for RowanSOM
    1. or for Rowan-Virtua SOM University and/or its units, or to or for an organized health
    care arrangement
    1. care arrangement in which
    RowanSOM
    1. Rowan-Virtua SOM and or its units participate, where the provision of
    the service
    1. the service involves the disclosure of individually identifiable health information from
    such entities
    1. such entities or arrangement, or from another business associate of such entities
    or arrangement
    1. or arrangement, to the person.
    2. Includes; Patient Safety Organizations (PSO) which receives patient safety

...

    1. from providers and analyses for purposes of compliance with PSQIA and the

...

    1. Patient Safety Rule, 42 CFR 3.10, et seq. Section 13408 includes Health

...

    1. Information Organization (HIO), E-prescribing gateway or Regional Health

...

    1. Information Organization which on a

...

    1. “routine basis”, maintains, oversees and governs

...

    1. the exchange of health related information between organizations, as BA.

...

  1.  Workforce

...

  1. – Faculty, employees, students, volunteers, trainees, and other persons whose conduct,

...

  1.  in the performance of work for

...

  1. Rowan-Virtua SOM and/or its units, is under the direct control of

...

  1. such entity(ies), whether or not they are paid by Rowan University SOM.

...

  1. "HITECT ACT" - Section 13402 of the Health Information Technology for Economic and Clinical Health (HITECH) Act, part of the American Recovery and Reinvestment Act of 2009 (ARRA) that was enacted on February 17, 2009.

V.   REFERENCES

...

  1. 45 CFR 160.103(a), Code of Federal Regulations, Title 45, Part 164, Section 103, Subpart A, General Administrative Requirements, General Provisions, Definitions

...

  1. 45 CFR 164.501(e), Code of Federal Regulations, Title 45, Part 164, Section 501, Subpart E, Security and Privacy, Definitions, Privacy of Individually Identifiable Health Information

...

  1. 45 CFR 164.502(e), Code of Federal Regulations, Title 45, Part 164, Section 502, Subpart E, Security and Privacy, Uses and Disclosures of Protected Health Information: General Rules, Privacy of Individually Identifiable Health Information

...

  1. 45 CFR 164.504(e), Code of Federal Regulations, Title 45, Part 164, Section 504, Subpart E, Security and Privacy, Uses and Disclosures: Organizational Requirements, Privacy of Individually Identifiable Health Information

...

  1. 45 CFR 164.532 (d) and (e), Code of Federal Regulations, Title 45, Part 164, Section 532, Subpart E, Security and Privacy, Uses and disclosures: Organizational requirements, Privacy of Individually Identifiable Health Information and (d) Standard: Effect of Prior Contracts or Other Arrangements with Business Associates

...

  1. Section 13404 and 13410(d) of the HITECH

...

  1. Act - Breach Notification Interim Final Regulation (74 FR 42740) - August 2009.

...

  1. Uses and Disclosures of Health Information With and Without an Authorization

...

  1. Omnibus Privacy Final Rule 2013

...

  1. Standards for Privacy of Individually Identifiable Health Information

VI.  POLICY

...

  1. Requirements:
      RowanSOM
      1. Rowan-Virtua SOM and/or its units may only allow an individual or entity that is not part of its workforce that provides certain services to
      RowanSOM
      1. Rowan-Virtua SOM and/or its units, or performs a function or activity on its behalf, to create or receive PHI without an authorization if the individual or entity:
        1. meets the definition of a business associate as described above, and
        2. enter into a written business associate contract with
        RowanSOM
        1. Rowan-Virtua SOM that meets the elements in 45 CFR 164.504(e) with
        RowanSOM
        1. Rowan-Virtua SOM.
      2. To determine whether the person or entity is required to enter into a business associate contract, use the following guidelines with the attached flowchart (
      EXHIBIT A
      1. Attachment 1):
        1. No contract is needed with members of the workforce as defined in the definition. An independent contractor may be considered a member of the workforce if
        RowanSOM
        1. Rowan-Virtua SOM exercises supervision and control over the person as it would if the independent contractor was an employee.
        2. A contract is necessary with persons who meet the definition of a business associate. (Since business associates access PHI without obtaining authorizations from the individuals to whom the PHI pertain, it is important that units do not inappropriately classify a person as a business associate and therefore fail to obtain the required authorization).

         
        1. A business associate is someone who does the following:
          1. Performs or assists in the performance of a function or activity on behalf of RowanSOM andRowan-Virtua SOM and/or its units including claims processing or administration, data analysis, processing or administration, utilization review, quality assurance, billing, benefit management, practice management, re-pricing, and any other function regulated by 45 CFR 164.504.
            For examples see EXHIBIT B attachment 2 for a list of specific types of persons, entities, and services that may qualify as a business associate provided that they meet all the elements discussed in this policy and procedure (i.e. the person will perform a function on behalf of RowanSOM Rowan-Virtua SOM that is not for the purposes of treatment only, etc).
          2. Provides legal, auditing, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, paper recycling, shredder companies, transcription services, record copy services, offsite storage, information technology (IT) services where confidentiality, integrity or availability of ePHI is at risk, including software/hardware support of computing medical devices, and/or application services such email, web or database services or financial services for Rowan University.
          Researchers 
          1. Researchers - This is not a covered function for purposes of a business associate contract.
          2. Financial
          Transactions 
          1. Transactions - No business associate agreement is required with a financial institution if it only processes consumer-conducted financial transactions in payment for health care.
            For example, a bank that processes credit or debit card transactions or clears checks for a hospital would not be considered a business associate. Although some PHI of the patient is disclosed to a financial institution in this example, such as the
          patient's
          1. patient’s identity and perhaps some health information (e.g., the procedure performed), these facts do not create a business associate relationship because the bank is not acting on behalf of the hospital in performing
          its functions
          1. its functions. The hospital is not in the business of directly processing credit card transactions or cashing checks.
        2. No contract is needed when the person or
        entity's
        1. entity’s function or service does not involve the use and disclosure of PHI, and where access to PHI by such persons would be de minimus or incidental, if at all.
          For example, it is not required that
        RowanSOM
        1. Rowan-Virtua SOM enter into a contract with janitorial services, waste disposal of sealed materials, or equipment repair because the performance of such services does not involve the use and disclosure of PHI. In this case, any incidental contacts or disclosures are permitted under the federal privacy laws as an incidental disclosure, provided that reasonable safeguards are in place to prevent such disclosures.
        2. No contract is needed with another healthcare provider when the use or disclosure of the PHI is for treatment purposes.
          1. If the relationship between the healthcare providers also includes involvement of PHI for operational or payment purposes, then a contract is necessary.
            Examples: A hospital enlists the services of another healthcare provider to assist in the
          hospital's
          1. hospital’s training of medical students. A physician, outside the workforce, serves as a medical director, or provides quality assurance or utilization management services through participation in hospital committees.
          2. For the definition and examples of the term treatment, payment, operations see
          EXHIBIT C
          1. attachment 3.
            1. If it is unclear as to whether the business associate definition has been met or if it is met, whether a contract is necessary, contact Legal Management for assistance. Generally, if it continues to be unclear as to whether there is a business associate relationship, no information should be shared with the person or entity without the patient's authorization.

    ...

    1. Responsibilities:
      1. Documentation of Business Associate Agreement
          RowanSOM
          1. Rowan-Virtua SOM and its units will document the satisfactory assurances of protecting health information through a written contract with the business associate that meets the applicable requirements of the Health Insurance and Portability Act (HIPAA), 45 CFR 164.504(e) and 164.308(b).
          2. All
          RowanSOM
          1. Rowan-Virtua SOM units must assure that the individuals and entities identified above agree in writing to the provisions in the attached business associate contract prior to engaging their services or allowing them to encounter any PHI. See
          EXHIBIT D
          1. attachment 4.
        1. Disclosure of Protected Health Information
            RowanSOM
              1. Rowan-Virtua SOM and its units may disclose protected health information (PHI) to a business associate and may allow a business associate to create or receive PHI on
            its behalf
              1. its behalf, if satisfactory assurances are obtained that the business associate
            will appropriately
              1. will appropriately safeguard the information. The CE and BA must maintain an accurate disclosure log, including who, what, when, where and why PHI was disclosed. The sale of PHI occurs when the CE or BA receive renumeration; directly or indirectly, from or on behalf of the recipient of PHI. The sale of PHI generally means disclosure of PHI. Additional individual authorization is required for disclosure of psychotherapy notes and marketing purposes.
            1. Responsibility of Individuals Authorized to Contract for Rowan University
              1. Any individual authorized to contract for
            RowanSOM
              1. Rowan-Virtua SOM, or who enters into any form of relationship on behalf of
            RowanSOM
              1. Rowan-Virtua SOM; in which PHI is exchanged or in which another entity has access to PHI other than a relationship with another treating provider relating to the treatment of patients, is responsible to obtain satisfactory assurances of protecting health information through the approved business associate contracting process and with the approved business associate contract. Failure to meet this responsibility is subject to disciplinary action up to and including termination and/or dismissal.
            RowanSOM
              1. Rowan-Virtua SOM and its units must require business associates to return or destroy all PHI in its possession at the termination of the contract when feasible and permitted by law.
              2. For purposes of internal monitoring of compliance with this policy and procedure, all
            RowanSOM
              1. Rowan-Virtua SOM units must maintain a log of all arrangements with parties outside of the workforce accessing business associate arrangements including:
                1. The name of the business associate.
                2. The type of services provided to
              RowanSOM
                1. Rowan-Virtua SOM, or the function or activity performed on behalf of
              RowanSOM
                1. Rowan-Virtua SOM.
                2. The date the business associate provisions were entered into.
                3. The date the performance or services begin.
                4. The type of protected health information that will be shared with the business associate.
                5. Whether any of the protected health information will be shared through electronic means.
              1. The above log must be made available to
            RowanSOM
              1. Rowan-Virtua SOM and the unit's privacy officers upon request.
              2. Business associates may only use and disclose PHI to the extent that
            RowanSOM
              1. Rowan-Virtua SOM would be allowed to use and disclose the information. See
            RowanSOM
              1. Rowan-Virtua SOM policy, Uses and Disclosures of Health Information With and Without an Authorization. Only the information minimally necessary to complete the purpose of the service or function may be shared.

          VII.

          ...

          ATTACHMENTS

          1. Attachment 1, Is a Person or Entity a "Business Associate" and Required to Enter Into a Written Business Associate Contract?
          2. Examples Attachment 2, Examples of Potential Business Associates
          3. TreatmentAttachment 3, Treatment, Payment and Health Care Operations
          4. Business Attachment 4, Business Associates Agreement Involving the Access to Protected Health Information

           

          By Direction of the President:

           

           

          Signature on file

                                                                                                                 

          RowanSOM Chief Compliance and Privacy Officer

           

           

           

          By Direction of the President:

           

           

          Signature on file

                                                                                                                 

          Rowan Security Officer

           

          ...

          VIII. NON-COMPLIANCE AND SANCTIONS

          Any individual who violates this policy shall be subject to discipline up to and including dismissal from the University in accordance with their union and University rules.  Civil and criminal penalties may be applied accordingly.  Violations of this policy may require retraining and be reviewed with employee during the annual appraisal process. The Deans of each College, Vice Presidents, and University President, with the assistance of the Department of Human Resources, will enforce the sanctions appropriately and consistently to all violators regardless of job titles or level within the University and in accordance with bargaining agreements for represented employees. Any sanction costs or fines will be borne by the Department and the Department Chair or VP will determine how these funds will be assigned.

          By Direction of the President:


          Signature on file

                                                                                                                 

          Chief Audit, Compliance and Privacy Officer



          By Direction of the President:


          Signature on file

                                                                                                                 

          Chief Information Security Officer


          ATTACHMENT 1
          Is a Person or Entity a "Business Associate" and 
          Required to Enter Into a Written Business Associate Contract?

          ...





          Image Added


          ATTACHMENT 2 
          Examples of Potential Business Associates 

          (This is not an all-inclusive list, nor is every arrangement listed necessarily a business associate. Use the attached flowchart and policy and procedure to analyze whether the relationship is a business associate relationship under

          ...

          HIPAA. Contact Legal Management at 2-4705 for assistance in the analysis.)

          ...

          Accountants

          Accounting services and firms

          Accreditation services

          Actuarial services

          Actuarial specialists

          Adjudication services

          Administrative services

          Advertisers

          Architects, builders, and contractors

          Asset-based lenders to healthcare facilities

          Attorneys

          Auditors

          Billing service companies

          Bulk mailing services

          Care management programs

          Civic groups and other local groups help out on ad hoc basis with patients who are hospitalized for a traumatic event or complicated illness (e.g., Shrine Temples, Ronald McDonald House)

          Coding providers and experts

          Community health management information systems

          Computer maintenance services and companies

          Consulting services

          Contract Research Organization – An entity used by pharmaceutical and device manufactures to monitor clinical research trials

          Copy services

          Data aggregation services

          Device manufactures

          Document storage and destruction vendors

          Financial service companies

          Government health data systems

          Hardware vendors

          Healthcare consultants (e.g., risk management, information technology, billing, coding and management)

          Hospital associations (National and State)

          HVAC vendors

          Independent contractors

          ATTACHMENT 

          ...

          (continued) 
          Examples of Potential Business Associates


          Independent service organizations (ISO) offering clinical/biomedical engineering services

          Insurance brokers

          Interpreter services (both deaf and foreign language)

          Janitorial services; waste disposal and recycling services and companies

          Law firms, its staff and employees

          Lobbyists

          Mailing houses

          Maintenance contractors

          Management services

          Marketing services or firms

          Medical equipment testing/ repair services

          Medical or Physician associations (National and State)

          Medical record moving companies

          Medical record storage companies

          Medical record transcription services

          Medical software vendors

          Microfilm conversion providers

          Organ and Tissue Banks

          Organ procurement organization

          Outsourced document shredders

          Patient advocates

          Pharmaceutical companies

          Pharmaceutical manufacturers

          Pharmaceutical representatives

          Plasma Donor Centers

          Printing companies (ID cards and other member materials)

          Private health data systems

          Professional liability insurance carriers

          Recycling services and companies

          Software vendors

          Sperm Banks

          Temporary Staffing Companies

          Third-party administrators

          Trade associations

          Utilization management vendors

          Value added networks

          Vendors to business associates if involving the disclosure of independently identifiable health information

          Waste disposal services and companies

           

          ...

          ATTACHMENT 3

          Treatment, Payment and Health Care Operations 

          ...


          1. "Treatment" - the provision, coordination, or management of health care and related services by one or more health care providers, including:
            1. the coordination or management of health care by a health care provider with a third party;
            2. consultation between health care providers relating to a patient; or
            3. the referral of a patient for health care from one health care provider to another. 

          ...

          1. "Payment" - the activities undertaken to obtain payment for the provision of healthcare; and relates to the individual to whom health care is provided and includes, but is not limited to:
            1. Determinations of eligibility or coverage (including coordination of benefits or the determination of cost sharing amounts), and adjudication or subrogation of health benefit claims;
            2. Billing, claims management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess of loss insurance), and related health care data processing;
            3. Obtaining information about the location of the individual is a routine activity to facilitate the collection of amounts owed and the management of accounts receivable, and, therefore, would constitute a payment activity.
            4. Debt collection is recognized as a payment activity.
            5. Review of health care services with respect to medical necessity, coverage under a health plan, appropriateness of care, or justification of charges;
            6. Utilization review activities, including pre-certification and pre-authorization of services, concurrent and retrospective review of services; and
            7. Disclosure to consumer reporting agencies of any of the following protected health information relating to collection of reimbursement:
              1. Name and address;
              2. Date of Birth;
              3. Social Security Number;
              4. Payment history;
              5. Account number; and
              6. Name and address of the health care provider and/or health plan.

          ...

          1. "Health Care Operations" - any of the following activities:
            1. Conducting quality assessment and improvement activities, including outcomes evaluation and development of clinical guidelines, population-based activities relating to improving health or reducing health care costs, protocol development, case management and care coordination, contracting of health care providers and patients with information about treatment alternatives; and related functions that do not include treatment;
            2. Reviewing the competence or qualifications of health care professionals, evaluating practitioner and provider performance, health plan performance, conducting training programs in which students, trainees, or practitioners in areas of health care learn under supervision to practice or improve their skills as health care providers, training of non-health care providers, accreditation, certification, licensing, or credentialing activities;
            3. Conducting or arranging for medical review, legal services and auditing functions, including fraud and abuse detection and compliance programs;
            4. Business planning and development, such as conducting cost-management and planning-related analyses related to managing and operating the entity, including formulary development and administration, development or improvement of methods of payment or coverage policies; and
            5. Business management and general administrative activities of Rowan University, including, but not limited to:
              1. Resolution of internal grievances;
              2. Due diligence in connection with the sale or transfer of assets to a potential successor in interest, if the potential successor in interest is a covered entity or, following completion of the sale or transfer, will become a covered entity.

           

          ATTACHMENT 4

          Business Associates Agreement Involving the Access to Protected Health Information 

          This Business Associate Agreement Agreement

          Is Related To and a Part of the Following

          Underlying Agreement:

          __________________________________________
          Effective Date of Underlying Agreement:__________School/Unit: _____________________

          Effective Date of Underlying Agreement:__________

          VendorSchool/Unit: ___________________________________

          Business Associate Agreement
          Involving the Access to Protected Health Information 

          ...

                1. Any inadvertent disclosure by a person who is otherwise authorized to access PHI at a Covered Entity or Business Associate to another, similarly authorized person at the same Covered Entity, Business Associate or organized health care arrangement in which the Covered Entity participate and such information received as a result of such disclosure is not further used or disclosed in an impermissible manner.

          ...

              1. Unsecured PHI means PHI not rendered unusable, unreadable, or indecipherable to unauthorized individuals through the use of technology or methodology specified by the Secretary of HHS. PHI of a patient who has been deceased for more than fifty (50) years [164.502(f)].

          ...

          1. Business Associate shall not use or disclose PHI other than as permitted or required by the Underlying Agreement, this BAA, and/or as Required By Law. Business Associate shall immediately notify Covered Entity of any use or disclosure of PHI in violation of this BAA.

          ...

                    1. Be made to the Covered Entity without unreasonable delay and in no event later than ten (10) days following the discovery of a breach, except in the case of a Business Associate that is an agent of the Covered Entity, in which case the Business Associate must provide the Covered Entity with immediate notification of the breach, except where law enforcement officials determine that a notification would impede a criminal investigation or cause damage to national security. Unless the language in the underlying agreement between the parties indicates that a Business Associate is an independent contractor, then the Business Associate shall be considered an agent of Rowan University for purposes of breach notification.

           

                    1. To the extent possible, provide the identity of each Individual whose Unsecured PHI was, or is reasonably believed to have been, Breached, and any other information that the Covered Entity is required to include in the notice to affected Individuals under 45 C.F.R. 164.404(c), either at the time of notice of Breach to the Covered Entity or as promptly thereafter as information becomes available. Include information in substantially the same form as the "Notification To the Covered Entity About A Breach of Unsecured Protected Health Information" available to Business Associates at RowanSOM website at https://www.rowan.edu/compliance

          DISCLOSURES OF PERSONALLY IDENTIFIABLE HEALTH INFORMATION TO BUSINESS ASSOCIATES 
          D.Business Associate is subject to the same legal requirements to cure, terminate or report violations to the Secretary of HHS under the same duty and in the same manner as Covered Entity. 
          E. Business Associate shall mitigate, to the extent practicable, any harmful effect known to it resulting from an unauthorized use or disclosure of PHI or Breach of Unsecured PHI. 
          F. Business Associate shall ensure that any agent, including a subcontractor, to whom it provides PHI  received from, or (ii) created or received by Business Associate on behalf of, a Covered Entity agrees, in writing, to the same restrictions and conditions that apply through this BAA to Business Associate with respect to such PHI. 
          G.Business Associate  shall provide Covered Entity access to its premises for a review and demonstration of its internal practices and procedures for safeguarding PHI and, (ii) to the extent applicable, shall provide access for inspection and copying of PHI in a Designated Record Set at reasonable times at the request of Covered Entity or, as directed by Covered Entity, to an Individual (45 C.F.R. 164.524). If Business Associate maintains an Electronic Health Record, Business Associate shall provide such information in electronic format to enable Covered Entity to fulfill its obligations under the HITECH Act. (42 U.S.C. §17935(e)). 
          H.Business Associate shall, upon request with reasonable notice, provide Covered Entity with an accounting of uses and disclosures of PHI provided to it by Covered Entity. 
          I. Business Associate agrees to use, disclose and request  only the minimum necessary PHI, as defined by law, and (ii) to the extent practicable, only the limited data set of PHI excluding direct identifiers, as defined in 45 C.F.R. 164.514(e)(2). 
          J.Business Associate shall document such disclosures of PHI and information related to such disclosures as would be required for a Covered Entity to respond to a request by an Individual for an accounting of disclosures of PHI (45 C.F.R. 164.528). Should a Covered Entity or an Individual request an accounting of disclosures of PHI pursuant to 45 C.F.R. 164.528, Business Associate agrees to promptly provide Covered Entity with information in a format and manner sufficient to respond no later than sixty (60) days after receipt of such request, subject to specific statutory exceptions. 
          K.Business Associate shall make its internal practices, books and records, including policies and procedures, relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of, Covered Entity, available to Covered Entity at the request of Covered Entity, or the Secretary of HHS, for purposes of the Secretary determining Covered Entity's compliance with HIPAA and/or the HITECH Act in the time, manner and place designated by the Covered Entity and/or the Secretary. 
          L.To the extent applicable, Business Associate shall make any amendment(s) to PHI in a Designated Record Set that Covered Entity directs or agrees to, no later than sixty (60) days after receipt of such request from a Covered Entity or Individual. 
          M. Business Associate agrees to abide by the limitations on marketing communications to Individuals regarding the purchase and use of products or services set forth in the HITECH Act and the HITECH Regulations. 
          N.Business Associate agrees and acknowledges that the administrative rules governing, and the civil and criminal penalties for violating, HIPAA, the HITECH Act, the HIPAA Regulations and the HITECH Regulations, apply to it in the same manner as they apply to Covered Entity, as more fully set forth at RowanSOM website at https://www.rowan.edu/compliance 
          IV. Term and Termination 
          A. Term. The term of this BAA shall be effective as of the effective date of the Underlying Agreement and shall terminate when all of the PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with the termination provisions of this Section IV. 
          B. Termination for Cause. Upon Covered Entity's knowledge of a material breach by Business Associate, Covered Entity shall either:

                1. Provide an opportunity for Business Associate to cure the breach or end the violation, and terminate this BAA and the Underlying Agreement if Business Associate does not cure the breach or end the violation within the time specified by Covered Entity;

          ...

          1. Miscellaneous

           

            1. Independent Contractor. None of the provisions of this BAA and/or the Underlying Agreement are intended to create nor shall be deemed or construed to have created any relationship between the

          Parties other than that of independent entities contracting with each other unless otherwise explicitly stated in this BAA or the Underlying Agreement.

            1. Detrimental Reliance By Covered Entity. Business Associate agrees and acknowledges that its covenants, duties, obligations and assurances herein shall be detrimentally relied upon by Covered Entity in choosing to commence or continue a business relationship with Business Associate. Covered Entity shall not be liable to Business Associate for any claim, loss, or damage relating to Business Associate's use or disclosure of any information received from Covered Entity or from any other source.

           

            1. Regulatory References. Any reference herein to law means the law as in effect or as amended.

           

            1. Construction. The BAA shall be construed broadly and any ambiguity shall be resolved in favor of a meaning that complies and is consistent with applicable law.

           

            1. Severability. In the event that any provision of this BAA violates any applicable statute, ordinance or rule of law in any jurisdiction that governs this BAA, such provision shall be ineffective to the extent of such violation without invalidating any other provision of this BAA.

          ...

          ___

          Vendor: ___________________________________________

          ATTACHMENT 4
          Rowan-Virtua SOM BAA-2019.doc 

          View file
          nameRowanSOM BAA-2019.doc
          height250

              1. Covered Entity's Notices To Business Associate. Covered Entity's Notices to Business Associate are available on Rowan University's website at https://www.rowan.edu/compliance Such Notices include, but are not limited to,  any limitations in the Covered Entity's Notices of Privacy Practices that may affect the Business Associate, (ii) any changes in, or revocation of, permission by an Individual to use or disclose PHI, or (iii) any restriction in the use or disclosure of PHI that Covered Entity has agreed to.

           

              1. Compliance With State Law. Business Associate agrees and acknowledges that as the holder of individually identifiable health information it is subject to New Jersey law. In the event of any conflict between federal health care laws and New Jersey law, the Business Associate shall comply with the more restrictive provision.

           

              1. Conflict Among Contracts. Should there be conflict between the terms of this BAA and any other contract between the Parties (either previous or subsequent to the date of this BAA), the terms of this BAA shall control unless the Parties, in a subsequent writing, specifically otherwise provide.

           

              1. Modification. This BAA may only be modified by a writing signed by the Parties. The Parties agree to take such action subsequent to this BAA as necessary to amend the BAA from time to time as necessary for the Parties to comply with the requirements of any applicable law.

          ...

                                                                                          

                       YES                                                     

           

           
            

           

           

           

                                                                                                    NO

                    

           

           
           

          Is the person or entity providing a function or activity for or on behalf of the unit?  (See attached definition of treatment, payment and operations).

          OR

          Is the person or entity providing legal, actuarial, accounting, consulting, data aggregation, management, administration, accreditation, or financial services?

           

          (See also attached list for examples of potential types of functions and services.)

           

           

           

           

           

           

                 

           

                     NO   

                                                                                         

                         

           

                         

                                                                                                         

           

                                                                                                  

           

                                                                                                           YES                              

                                                                                                                                   

           

          Does the function to be conducted or service provided by the person or entity necessitate the use or disclosure of protected health information that is beyond incidental and de minimis?

           

           

                                 

           

                   

                      NO

           

           

           
            

           

           

           

                 

                     YES

           

           

           
           

          Does the use or disclosure of protected health information to the person or entity concern only the “treatment” of an individual?

           

           

           

           

           

           

                     YES

                                                         

                         

                     

                                                                                                                                                                 

                                                                                                                                                      NO