|
REV:01-20-23 MI
<br />2.6.5. A brief description of any action taken to investigate the Breach, mitigate
<br />losses, and to protect against any further Breaches.
<br />2.6.6. Contact procedures for Individuals to ask questions or learn additional
<br />information, which shall include a toll-free telephone number, an e-mail
<br />address, web site, or postal address.
<br />2.7. If a law enforcement official determines that a notification or notice would impede a
<br />criminal investigation or cause damage to national security, such notification, notice
<br />or posting shall be delayed in accordance with 45 CFR 164.412.
<br />Upon Covered Entity’s request, Business Associate will provide notice of Breach to
<br />the Individual(s) affected and such notice shall include, to the extent possible, the
<br />information listed in 2.6., unless, upon occurrence of a Breach, Covered Entity
<br />requests to disseminate or Business Associate and Covered Entity agree that Covered
<br />Entity will disseminate the notice(s). Any notice provided by Covered Entity to the
<br />Individual(s) shall comply with the content requirements listed in section 2.6., as well
<br />as any requirements provided under HIPAA, HITECH, and other applicable
<br />government guidance. Any notice required to be provided to HHS will be provided by
<br />Covered Entity. Business Associate agrees to report to Covered Entity any Use or
<br />Disclosure of PHI not provided for by this Exhibit and/or any Security Incident of
<br />which it becomes aware, provided that notice is hereby deemed given for
<br />Unsuccessful Security Incidents and no further notice of such Unsuccessful Security
<br />Incidents shall be given. For purposes of this Section, “Unsuccessful Security
<br />Incidents” mean, without limitation, pings and other broadcast attacks on Business
<br />Associate’s firewall, port scans, unsuccessful log-on attempts, denial of service
<br />attacks, and any combination of the above, as long as no such incident results in
<br />unauthorized access, acquisition, Use, or Disclosure of Protected Health Information.
<br />Notification(s) under this Section, if any, will be delivered to contacts identified by the
<br />Employer by any means Business Associate selects, including through e-mail.
<br />Business Associate’s obligation to report under this Section is not and will not be
<br />construed as an acknowledgement by Business Associate of any fault or liability with
<br />respect to any Use, Disclosure, or Security Incident.
<br />2.8. Business Associate shall require each of its subcontractors, agents, or brokers, that
<br />creates, receives, maintains, or transmits PHI on behalf of Covered Entity to enter into
<br />a written agreement with Business Associate that provides satisfactory assurances that
<br />the subcontractor will appropriately safeguard that information, including without
<br />limitation the subcontractor’s agreement to be bound by the same restrictions and
<br />conditions that apply to Business Associate with respect to such information.
<br />2.9. Business Associate agrees to make internal practices, books, and records, including
<br />policies and procedures and PHI relating to the use and disclosure of PHI available to
<br />the Secretary, within ten (10) Business Days after receipt of written request or
<br />otherwise as designated by the Secretary for purposes of the Secretary determining
<br />Covered Entity’s compliance with the Privacy Rule
<br />2.10. Business Associate agrees to document disclosures of PHI and information related to
<br />such disclosures as required for Covered Entity to respond to a written request by an
<br />Individual for an accounting of disclosures of PHI in accordance with 45 CFR
<br />164.528. Business Associate will not be obligated to record disclosures of PHI or
<br />otherwise account for disclosures of PHI if neither Covered Entity nor Business
<br />Associate is required to account for such disclosures pursuant to the Privacy Rule.
<br />2.11. Business Associate agrees to provide to Covered Entity or, upon Covered Entity’s
<br />request, to an Individual, within ten (10) Business Days after receipt of written
<br />request, information collected in accordance with Section 2.10 of this Exhibit, in order
<br />ATTY/AGR.2023.010/Navia Benefit Solutions (Navia Services (Dental HRA) 2023) (Page 38 of 42)
|