Laserfiche WebLink
(b) Neither Sponsor nor Covered Entityshall request Business Associate to use or disclose PHI <br />in any rnanner that would not be permitted or required by law if done by covered Entity, <br />(c) Covered 'Entity shall notify Business Associate in writing of any restriction to the use or <br />disclosure of PI -11 that Covered Entityhas agreed to in accordance with e15 CTR § 164.522. <br />rND-F'MNjfI AjjQ-N. <br />(ti) Business Associate agrees to indemnify, defend, and hold harmless the covered Esutity, its <br />trustees, officers, directors, employees, agents, or representatives, from anyclaim or penaltyarising out of any <br />improper use and/or disclosure of PI -H r"rt violation of the PrivacyRegulation, to the extent that such improper <br />use and/or disclosure resulted from Business Associate's negligence or failure to comply with the teams of <br />this Agreement or the Privacy Regulation. <br />(b) The Sponsor and Covered Entity agree to indemnify, defend and hold harmless Business <br />Associate and/or all of Business Associate's officers, directors, employees, agents, or representatives, from <br />any claim or penalty from any improper use anti/or disclosure of PPII, to the extent that such improper use <br />and/or disclosure resulted from the Sponsor's or Covered Emityrs negligence, failure to comply with the <br />terms of this Agreement or the Privacy Regulation, or was based upon the Sponsor's or Covered Entity's <br />written direction to use and/or disclose PI -11 in the manner challenged. <br />SLIORM <br />Business Associate agrees to; <br />a) Implement safeguards that reasonably and appropriately protect the confidentiality; <br />integrity, and availability of the electronic PHI that it creates, receives, maintains, or transnuts on behalf of <br />the Covered Entity; <br />u) Ensure that any Subcontractor, to whom it provides this infornlation agrees to <br />implement reasonable and appropriate safeguards; <br />iii) Report on a quarterly basis to the Covered Entity, in writing, any Security Incident <br />involving Covered Entity's data. If, however, a Security Incident results in the unauthorized disclosure of <br />Unsecured PHI, Business Associate shall notify Covered Entity in accordance with the Breach notification <br />provisions below. <br />iv) Notify Covered Entity no latter than ten (10) days after discovery of a Breach of <br />Unsecured PER,' <br />v) Performthe four factor riskassessrnent of anyMaeh that is discovered in accordance <br />wth the HIPAA Rules to determine if notification is required, and advise Covered Entityof its findings. <br />Covered Entity has 60 flays from the discovery date of s. reportable Breach to report said <br />Breach to tine Individual and 1-I1-1.8 (ifl3reach involves 500 or more Individuals.) <br />I<.unnwi & Assaniaw - tireme 40,151271 <br />business Assoeli , Commut (Scatti nday) <br />(Rev.07/29/13j <br />Page 5 of S <br />