BUSINESS ASSOCIATE AGREEMENT

This Business Associate Agreement (“Agreement“) is entered into by and between the healthcare provider, healthcare organization, or other HIPAA Covered Entity that executes or incorporates this Agreement by reference (the “Covered Entity“), and Remote Patient Devices, LLC. (the “Business Associate“).

This Agreement is incorporated into and forms a part of any Services Agreement, Master Services Agreement, Statement of Work, Order Form, or other written agreement (the “Underlying Agreement”) under which Business Associate provides services to Covered Entity that involve the creation, receipt, maintenance, transmission, access to, or use of Protected Health Information (“PHI“). To the extent of any conflict between this Agreement and any underlying services agreement regarding the protection or use of PHI, the terms of this Agreement shall control.

I. Purpose

The parties enter into this Agreement to comply with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA“), the Health Information Technology for Economic and Clinical Health Act (“HITECH“), and their implementing regulations, including 45 C.F.R. Parts 160, 162, and 164, as amended from time to time.

This Agreement governs the use, disclosure, safeguarding, and protection of PHI received, created, maintained, or transmitted by Business Associate on behalf of Covered Entity.

II. Term

This Agreement shall become effective upon the execution of a Services Agreement incorporating this Agreement by reference.

This Agreement shall remain in effect for so long as Business Associate maintains or has access to PHI on behalf of Covered Entity, until the Underlying Agreement, or terminated in accordance with this Agreement, whichever occurs earlier.

III. Obligations of Business Associate

To the extent Business Associate creates, receives, maintains, transmits, or otherwise has access to PHI on behalf of Covered Entity, Business Associate shall:

(a) Compliance with HIPAA

Comply with all applicable provisions of HIPAA, HITECH, and their implementing regulations applicable to Business Associates, including applicable requirements of 45 C.F.R. Parts 160, 162, and 164.

(b) Permitted Uses and Disclosures

Use or disclose PHI only:

  • as permitted or required by this Agreement;
  • as required by applicable law; or
  • as necessary to perform services for Covered Entity.

Business Associate shall not use or disclose PHI in any manner that would violate HIPAA if performed by Covered Entity.

(c) Safeguards

Implement and maintain appropriate administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of PHI and Electronic Protected Health Information (“ePHI“). Business Associate shall maintain written policies and procedures reasonably designed to comply with applicable HIPAA requirements.

(d) Security Incidents and Breach Notification

Business Associate shall notify Covered Entity without unreasonable delay, and in no event later than the time required under applicable law, after becoming aware of:

  • any Breach of Unsecured Protected Health Information, as defined under 45 C.F.R. §164.402;
  • any Security Incident affecting PHI;
  • any unauthorized acquisition, access, use, or disclosure of PHI; or
  • any use or disclosure not permitted under this Agreement.

Such notification shall include all information reasonably available to Business Associate necessary for Covered Entity to comply with applicable breach notification obligations.

(e) Subcontractors

Business Associate shall ensure that any subcontractor, vendor, agent, consultant, or other third party that creates, receives, maintains, transmits, accesses, or uses PHI on its behalf agrees in writing to restrictions and conditions that are at least as protective as those contained in this Agreement and as required under HIPAA.

(f) Individual Rights

To the extent applicable, Business Associate shall:

  • provide access to PHI in a Designated Record Set as required under 45 C.F.R. §164.524;
  • make amendments to PHI as directed by Covered Entity pursuant to 45 C.F.R. §164.526; and
  • provide information necessary for Covered Entity to satisfy requests for an accounting of disclosures pursuant to 45 C.F.R. §164.528.

(g) Accounting of Disclosures

Business Associate shall maintain documentation of disclosures of PHI sufficient to enable Covered Entity to respond to requests for an accounting of disclosures under HIPAA, including the information required by applicable regulations.

(h) Government Access

As may be required by law, Business Associate shall make its internal practices, books, records, policies, and procedures relating to the use and disclosure of PHI available to the Secretary of the United States Department of Health and Human Services for purposes of determining compliance with HIPAA.

(i) Minimum Necessary

Business Associate shall request, use, disclose, and limit PHI consistent with the HIPAA Minimum Necessary Standard, where applicable.

(j) Standard Transactions

If Business Associate conducts HIPAA Standard Transactions on behalf of Covered Entity, Business Associate shall comply with the applicable requirements of 45 C.F.R. Part 162.

IV. Permitted Uses of Protected Health Information

Except as otherwise prohibited by law, Business Associate may use PHI to perform services for Covered Entity, for proper management and administration of Business Associate, to carry out Business Associate’s legal responsibilities, as otherwise permitted under 45 C.F.R. §164.504(e) and other applicable HIPAA regulations, and as required by law.

V. De-Identified Information

Business Associate may create, use, disclose, and retain information that has been de-identified in accordance with 45 C.F.R. §164.514, provided that such information cannot reasonably be used to identify any individual and no re-identification key or code is disclosed, except as permitted by applicable law.

VI. Termination

Covered Entity may immediately terminate this Agreement and any related Services Agreement if it reasonably determines that Business Associate has materially breached this Agreement and:

  • the breach cannot reasonably be cured; or
  • Business Associate fails to cure the breach within thirty (30) days after receiving written notice from Covered Entity.

Covered Entity may immediately suspend further disclosures of PHI if reasonably necessary to protect PHI or comply with HIPAA.

If termination is not feasible, Covered Entity may report the violation to the Secretary of the U.S. Department of Health and Human Services as required by applicable law.

VII. Return or Destruction of Protected Health Information

Upon termination of this Agreement, Business Associate shall, at Covered Entity’s direction:

  1. return all PHI;
  2. securely destroy all PHI; or
  3. continue to protect PHI if return or destruction is not feasible.

If Business Associate determines that return or destruction is infeasible, Business Associate shall provide written notice describing the circumstances preventing return or destruction.

For any PHI retained due to infeasibility, Business Associate shall:

  • continue to comply with this Agreement;
  • limit further uses and disclosures to those that make return or destruction infeasible; and
  • maintain such protections until the PHI can be returned or destroyed or is otherwise no longer required to be retained by law.

VIII. Amendment

The parties agree to amend this Agreement as necessary to comply with changes in HIPAA, HITECH, or other applicable federal or state laws governing the privacy or security of PHI.

The Business Associate may also amend this Agreement for any other reason upon thirty (30) days’ prior notice to the Covered Entity, which notice may be provided by posting the revised Agreement or a notice of amendment on the website where this Agreement is publicly available. Such amendment shall become effective upon expiration of the 30-day notice period unless otherwise required by applicable law

IX. Interpretation

This Agreement shall be interpreted in a manner that permits the parties to comply with HIPAA, HITECH, and all applicable federal and state privacy and security laws.

Any ambiguity shall be resolved in favor of compliance with applicable law.

X. Definitions

Capitalized terms not otherwise defined in this Agreement shall have the meanings assigned to them under HIPAA, HITECH, and their implementing regulations, as amended from time to time.

XI. No Third-Party Beneficiaries

Nothing in this Agreement is intended to confer any rights, remedies, obligations, or benefits upon any person or entity other than the parties to this Agreement.

XII. Survival

The obligations of Business Associate regarding the confidentiality, privacy, security, use, disclosure, return, destruction, and protection of PHI shall survive the expiration or termination of this Agreement for so long as Business Associate retains any PHI.

XIII. Entire Agreement

This Agreement constitutes the complete agreement between the parties concerning the protection and handling of PHI and supersedes any prior understandings relating to the subject matter herein. This Agreement is intended to satisfy the requirements of 45 C.F.R. §164.504(e) and shall be incorporated by reference into any applicable Services Agreement between the parties.

Where this Agreement is incorporated by reference into an executed Services Agreement, no separate signature to this Agreement shall be required unless otherwise requested by either party.