Laserfiche WebLink
1.4. Individual. "Individual" shall mean the person who is the subject of Protected Health <br />Information as provided in 45 C.F.R. § 160.103 and shall include a person who qualifies as a <br />personal representative in accordance with 45 C.F.R. § 164.502(g). <br />1.5. Individually Identifiable Health Information. "Individually Identifiable Health Information" <br />shall have the same meaning as the term "individually identifiable health information in 45 <br />C.F.R. § 160.103. <br />1.6. Protected Health Information or PHI. "Protected Health Information" or "PHI" shall have the <br />same meaning as the term "protected health information" in 45 C.F.R. § 160.103, limited to <br />the information created or received by Business Associate from or on behalf of Covered Entity. <br />1.7. Required By Law. "Required By Law" shall have the same meaning as the term "required by <br />law" in 45 C.F.R. § 164.103. <br />1.8. Secretary. "Secretary" shall mean the Secretary of the federal Department of Health and Human <br />Services or that person's designee. <br />1.9. Security Incident. "Security Incident" shall have the same meaning as the term "security <br />incident" in 45 C.F.R. § 164.304. <br />1.10. Unsecured Protected Health Information. "Unsecured Protected Health Information" shall have <br />the same meaning as the term "unsecured protected health information" in 45 C.F.R. § 164.402, <br />limited to the information created or received by Business Associate from or on behalf of <br />Covered Entity. <br />2. Permitted Uses and Disclosures by Business Associate. <br />2.1. General. Except as otherwise specified in this Agreement, Business Associate may access, use <br />or disclose PHI to perform its obligations for, or on behalf of, Covered Entity provided that <br />Business Associate uses and discloses PHI in the following manner: <br />2.1.1 Consistent with the minimum necessary policies and procedures of Covered Entity; <br />and <br />2.1.2 Would not violate 45 C.F.R. Subpart E if done by Covered Entity, except as specified <br />in paragraphs 2.2 and 2.3 of this section <br />2.1.3 Consistent with the provisions of Chapter 70.02 RCW. <br />2.2. Other Permitted Uses. Except as otherwise limited by this Agreement, Business Associate may <br />use PHI it receives or creates in its capacity as a business associate of Covered Entity, if <br />necessary: <br />2.2.1. For the proper management and administration of Business Associate; <br />2.2.2. To carry out the legal responsibilities of Business Associate; or <br />2.2.3. To provide Data Aggregation services to Covered Entity that relate to the health care <br />operations of Covered Entity in accordance with the HIPAA Privacy Regulations. <br />Page 2 of 9 <br />