Laserfiche WebLink
(iii) Disclosure Information. With respect to any disclosure by the Business Associate of the Covered Entity's <br />Protected Health information that is not excepted from disclosure accounting under the HIPAA Rules, the <br />Business Associate will record the following Disclosure Information as applicable to the type of accountable <br />disclosure made: <br />(A) Disclosure information Generally. Except for repetitive disclosures of the Covered Entity's Protected <br />Health Information as specified below, the Disclosure Information that the Business Associate must record <br />for each accountable disclosure Is (1) the disclosure date, (2) the name and (if known) address of the entity <br />to which the Business Associate made the disclosure, (3) a brief description of the Covered Entity's <br />Protected Health Information disclosed, and (4) a brief statement of the purpose of the disclosure. <br />(B) Disclosure Information for Repetitive Disclosures. For repetitive disclosures of the Covered Entity's <br />Protected Health information that the Business Associate makes for a single purpose to the same person <br />or entity (including the Covered Entity), the Disclosure Information that the Business Associate must record <br />is either the Disclosure Information specified above for each accountable disclosure, or (1) the Disclosure <br />Information specified above for the first of the repetitive accountable disclosures; (2) the frequency, <br />periodicity; or number of the repetitive accountable disclosures; and (3) the date of the last of the repetitive <br />accountable disclosures. <br />(Iv) Availability of Disclosure Information. The Business Associate will maintain the Disclosure Information <br />for at least 6 years following the date of the accountable disclosure to which the Disclosure Information relates <br />(3 years for disclosures related to an Electronic Health Record, starting with the date specified by NHS). The <br />Business Associate will make the Disclosure Information available to the Covered Entity within twenty-five (25) <br />calendar days fallowing the Covered Entity's request for such Disclosure Information to comply with an <br />Individual's request for disclosure accounting. Effective as of the date specified by MHS, with respect to <br />disclosures related to an Electronic Health Record, the Business Associate shall provide the accounting directly <br />to an individual making such a disclosure request, if a direct response is requested by the individual, To the <br />extent the Business Associate is to carry out one or more of Covered Entity's obligation(s) under Subpart E of <br />45 CFR Part 164, comply with the requirements of Subpart E that apply to the covered entity in the <br />performance of such obligation(s); and make its internal practices, books, and records available to the <br />Secretary for purposes of determining compliance with the HIPAA Rules. <br />(d) Restriction Agreements and Confidential Communications, The Covered Entity shall notify the Business <br />Associate of any limitations in the notice of privacy practices of Covered Entity under 46 CFR §164.520, to the <br />extent that such limitation may affect the Business Associate's use or disclosure of Protected Health information. <br />The Business Associate will comply with any agreement that the Covered Entity makes that either (1) restricts use <br />or disclosure of the Covered Entity's Protected Health Information pursuant to 45 CFR §164.522(a), or (it) requires <br />confidential communication about the Covered Entity's Protected Health Information pursuant to 45 CFR <br />§164.522(b), ,provided that the Covered Entity notifies the Business Associate in writing of the restriction or <br />confidential communication obligations that the Business Associate must follow. The Covered Entity will promptly <br />notify the Business Associate in writing of the termination of any such restriction agreement or confidential <br />communication requirement and, with respect to termination of any such restriction agreement, instruct the <br />Business Associate whether any of the Covered Entity's Protected Health Information will remain subject to the <br />terms of the restriction agreement. Effective February 17, 2010 (or such other date specified as the effective date <br />by HHS), the Business Associate will comply with any restriction request If: (I) except as otherwise required by law, <br />the disclosure is to a health plan for purposes of carrying out payment or health care operations (and Is not for <br />purposes of carrying out treatment); and (11) the Protected Health Information pertains solely to a health care item or <br />service for which the health care provider involved has been paid out-of-pocket in full. <br />VII. Breaches and Security Incidents <br />(a) Reporting. <br />(1) Impermissible Use or Disclosure. The Business Associate will report to Covered Entity any use or <br />disclosure of Protected Health Information not permitted by this Agreement not more than twenty-five <br />(25) calendar days after Business Associate becomes aware of such non -permitted use or disclosure. <br />(11) Privacy or Security Breach. The Business Associate will report to the Covered Entity any use or <br />disclosure of the Covered EntityfsProtected Health Information not permitted by this Agreement of which It <br />becomes aware, including breaches of Unsecured Protected Health Information as required by 45 CFR <br />