Laserfiche WebLink
BMI Audit Services <br /> 2.5 Permitted Uses and Disclosures to Federal and State Authorities. Business Associate may <br /> use PHI to report violations of law to appropriate Federal and State authorities, consistent with <br /> Federal and State laws and regulations, provided that Business Associate believes in good faith <br /> that Covered Entity had engaged in conduct that is unlawful or otherwise violates professional or <br /> clinical standard, or that the care, services, or conditions provided by Covered Entity potentially <br /> endangers one or more patients, workers, or the public and the disclosure is to a health oversight <br /> agency or public health authority,or an attorney retained by or on behalf of Business Associate. <br /> SECTION 3 <br /> OBLIGATIONS OF BUSINESS ASSOCIATE <br /> 3.1 Use of PHI. Business Associate shall not use or further disclose PHI other than as expressly <br /> permitted or required by this Agreement or as required by law. However,Business Associate may <br /> use PHI for the purpose of managing its internal business processes relating to its functions under <br /> this Agreement. <br /> 3.2 Disclosure of PHI. Business Associate shall: <br /> (a) not disclose PHI to any person other than employees or <br /> subcontractors of Business Associate, except as approved by Covered <br /> Entity in writing and in accordance to any Notice of Privacy Practices <br /> provided to Business Associate by Covered Entity. Any such disclosure to <br /> a subcontractor shall be made only upon the execution of a separate business <br /> associate agreement as provided in Paragraph 3.5; <br /> (b) not disclose PHI to its employees unless Business Associate has <br /> advised them of Business Associate's obligations under this Agreement, <br /> and the consequences for employees and for Business Associate of violating <br /> them. Business Associate shall take appropriate disciplinary action against <br /> any employee who uses or discloses PHI in contravention of this <br /> Agreement; and <br /> 3.3 Appropriate Safeguards. Business Associate shall use appropriate safeguards to prevent <br /> use or disclosure of PHI other than as provided for by this Agreement. Business Associate shall <br /> provide Covered Entity with such information concerning such safeguards as Covered Entity may <br /> from time to time request. <br /> 3.4 Compliance with the Security Rule. The Business Associate will comply,when applicable, <br /> with the Security Rule with respect to EPI-II. <br /> 3.5 Subcontractors. Business Associate shall ensure that any subcontractors that create, <br /> receive, maintain, or transmit PHI on behalf of Business Associate agree to comply with the <br /> applicable requirements of HIPAA by entering into a Subcontractor Business Associate <br /> Agreement or other arrangement that complies with the Privacy Rule, Security Rule, Breach <br /> Notification Rule, and this Agreement. <br /> Business Associate Agreement 3 <br />