Laserfiche WebLink
10 <br />EXHIBIT B <br />BUSINESS ASSOCIATE AGREEMENT (“BAA”) <br />1.DEFINITIONS <br />(a)“Breach” shall mean, as defined in 45 C.F.R. § 164.402, the acquisition, access, <br />use or disclosure of Unsecured Protected Health Information in a manner not permitted by the <br />HIPAA Requirements that compromises the security or privacy of that Protected Health <br />Information. <br />(b)“Security Incident” shall mean, as defined in 45 C.F.R. § 164.304, the attempted <br />or successful unauthorized access, use, disclosure, modification, or destruction of information <br />or interference with system operations in an information system. <br />(c)All other capitalized terms used in this BAA shall have the meanings set forth in <br />the applicable definitions under the HIPAA Requirements. <br />2.GENERAL TERMS <br />(a)In the event of an inconsistency between the provisions of this BAA and a term <br />in HIPAA (as these terms may be expressly amended from time to time by the HHS or as a result <br />of interpretations by HHS, a court, or another regulatory agency with authorit y over the <br />parties), the interpretation of HHS, such court or regulatory agency shall prevail. <br />(b)Where provisions of this BAA are different from those mandated by the HIPAA <br />Requirements, but are nonetheless permitted by the HIPAA Requirements, the provisions of <br />this BAA shall control. <br />(c)Except as expressly provided in the HIPAA Requirements or this BAA, this <br />BAA does not create any rights in third parties. <br />3.SPECIFIC REQUIREMENTS <br />(a)Subcontractors. Business Associate agrees that as required by the HIPAA <br />Requirements, Business Associate shall enter into a written agreement with all Business <br />Associate Subcontractors that: (i) requires them to comply with the Privacy and Security Rule <br />provisions of this BAA in the same manner as required of Business Associate, and (ii) notifies <br />such Business Associate Subcontractors that they shall incur liability under the HIPAA <br />Requirements for non-compliance with such provisions. Accordingly, Bu siness Associate shall <br />ensure that all Business Associate Subcontractors agree in writing to the same privacy and <br />security restrictions, conditions and requirements that apply to Business Associate with respect <br />to Protected Health Information.