Laserfiche WebLink
REV:01-20-23 MI <br />2.6.5. A brief description of any action taken to investigate the Breach, mitigate <br />losses, and to protect against any further Breaches. <br />2.6.6. Contact procedures for Individuals to ask questions or learn additional <br />information, which shall include a toll-free telephone number, an e-mail <br />address, web site, or postal address. <br />2.7. If a law enforcement official determines that a notification or notice would impede a <br />criminal investigation or cause damage to national security, such notification, notice <br />or posting shall be delayed in accordance with 45 CFR 164.412. <br />Upon Covered Entity’s request, Business Associate will provide notice of Breach to <br />the Individual(s) affected and such notice shall include, to the extent possible, the <br />information listed in 2.6., unless, upon occurrence of a Breach, Covered Entity <br />requests to disseminate or Business Associate and Covered Entity agree that Covered <br />Entity will disseminate the notice(s). Any notice provided by Covered Entity to the <br />Individual(s) shall comply with the content requirements listed in section 2.6., as well <br />as any requirements provided under HIPAA, HITECH, and other applicable <br />government guidance. Any notice required to be provided to HHS will be provided by <br />Covered Entity. Business Associate agrees to report to Covered Entity any Use or <br />Disclosure of PHI not provided for by this Exhibit and/or any Security Incident of <br />which it becomes aware, provided that notice is hereby deemed given for <br />Unsuccessful Security Incidents and no further notice of such Unsuccessful Security <br />Incidents shall be given. For purposes of this Section, “Unsuccessful Security <br />Incidents” mean, without limitation, pings and other broadcast attacks on Business <br />Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service <br />attacks, and any combination of the above, as long as no such incident results in <br />unauthorized access, acquisition, Use, or Disclosure of Protected Health Information. <br />Notification(s) under this Section, if any, will be delivered to contacts identified by the <br />Employer by any means Business Associate selects, including through e-mail. <br />Business Associate’s obligation to report under this Section is not and will not be <br />construed as an acknowledgement by Business Associate of any fault or liability with <br />respect to any Use, Disclosure, or Security Incident. <br />2.8. Business Associate shall require each of its subcontractors, agents, or brokers, that <br />creates, receives, maintains, or transmits PHI on behalf of Covered Entity to enter into <br />a written agreement with Business Associate that provides satisfactory assurances that <br />the subcontractor will appropriately safeguard that information, including without <br />limitation the subcontractor’s agreement to be bound by the same restrictions and <br />conditions that apply to Business Associate with respect to such information. <br />2.9. Business Associate agrees to make internal practices, books, and records, including <br />policies and procedures and PHI relating to the use and disclosure of PHI available to <br />the Secretary, within ten (10) Business Days after receipt of written request or <br />otherwise as designated by the Secretary for purposes of the Secretary determining <br />Covered Entity’s compliance with the Privacy Rule <br />2.10. Business Associate agrees to document disclosures of PHI and information related to <br />such disclosures as required for Covered Entity to respond to a written request by an <br />Individual for an accounting of disclosures of PHI in accordance with 45 CFR <br />164.528. Business Associate will not be obligated to record disclosures of PHI or <br />otherwise account for disclosures of PHI if neither Covered Entity nor Business <br />Associate is required to account for such disclosures pursuant to the Privacy Rule. <br />2.11. Business Associate agrees to provide to Covered Entity or, upon Covered Entity’s <br />request, to an Individual, within ten (10) Business Days after receipt of written <br />request, information collected in accordance with Section 2.10 of this Exhibit, in order <br />ATTY/AGR.2023.010/Navia Benefit Solutions (Navia Services (Dental HRA) 2023) (Page 38 of 42)