This Business Associate Agreement ("Agreement") is entered into between:
COVERED ENTITY: Healthcare Provider (as defined in the Provider Registration)
BUSINESS ASSOCIATE: Sefton Health, Inc., d/b/a Sefton Healthcare Platform
31 E Newell Avenue
Rutherford, NJ 07070
Phone: (212) 729-7332
Email: admin@sefton.health
Sefton provides healthcare business administration services including but not limited to:
In performing these services, Sefton may create, receive, maintain, or transmit Protected Health Information (PHI) on behalf of the Covered Entity as necessary to provide the services specified in the underlying service agreement.
Terms used in this Agreement shall have the meanings assigned to them under:
(a) The Health Insurance Portability and Accountability Act of 1996 ("HIPAA")
(b) The Health Information Technology for Economic and Clinical Health Act ("HITECH Act")
(c) Their implementing regulations at 45 CFR Parts 160 and 164 (collectively, the "HIPAA Rules")
The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Business Associate, Covered Entity, Data Aggregation, Designated Record Set, Disclosure, Electronic Protected Health Information (ePHI), Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information (PHI), Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
A breach shall be treated as discovered by Business Associate as of the first day on which the breach is known to Business Associate or, by exercising reasonable diligence, would have been known to Business Associate. Business Associate shall be deemed to have knowledge of a breach if it is known, or by exercising reasonable diligence would have been known, to any person (other than the person committing the breach) who is an employee, officer, or other agent of Business Associate (determined in accordance with federal common law of agency).
Business Associate may use or disclose PHI only as follows:
(a) As necessary to perform the services specified in the underlying service agreement between Business Associate and Covered Entity;
(b) As required by law;
(c) For proper management and administration of Business Associate, provided that:
(i) The disclosures are required by law; OR
(ii) Business Associate obtains reasonable assurances from the third party that the PHI will be held confidential and used or further disclosed only as required by law or for the purpose for which it was disclosed to the third party, and the third party notifies Business Associate of any instances of which it is aware in which the confidentiality of the PHI has been breached;
(d) To provide data aggregation services relating to the health care operations of Covered Entity as permitted by 45 CFR 164.504(e)(2)(i)(B);
(e) To report violations of law to appropriate federal and state authorities, consistent with 45 CFR 164.502(j)(1).
Business Associate shall, to the extent practicable, use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose of the use, disclosure, or request, in accordance with 45 CFR 164.502(b) and 164.514(d). This provision shall not apply to:
(a) Disclosures to or requests by a health care provider for treatment;
(b) Uses or disclosures made to the individual;
(c) Uses or disclosures made pursuant to an individual's authorization;
(d) Disclosures made to the Secretary of HHS;
(e) Uses or disclosures that are required by law.
Business Associate may use PHI to create de-identified information in accordance with 45 CFR 164.514(a)-(c), provided that Business Associate does not attempt to re-identify or permit anyone else to re-identify such information. If de-identified information is re-identified, Business Associate may use or disclose such re-identified information only as permitted or required by this Agreement.
Business Associate shall not, directly or indirectly, receive remuneration in exchange for PHI unless: (a) the purpose of the exchange is for public health activities; (b) the purpose of the exchange is for research and the only remuneration received is a reasonable, cost-based fee to cover the cost of preparation and transmittal of the PHI; (c) the purpose of the exchange is for treatment and payment; or (d) the sale of PHI is otherwise permitted by the HITECH Act and HIPAA Rules.
Business Associate shall not use or disclose PHI for marketing purposes without a valid authorization from the individual, except as permitted by 45 CFR 164.508(a)(3).
Business Associate shall not use or disclose PHI to develop, train, fine-tune, or improve any artificial-intelligence or machine-learning model โ whether first-party or third-party, general-purpose or special-purpose โ except solely to provide the contracted services to the Covered Entity that supplied the PHI, and never to build or improve a model offered to other customers. This prohibition is not waivable by Covered Entity permission and flows down to every subcontractor that processes PHI on Business Associate's behalf (see Section 4 flow-down). Automated transcription, documentation-support, translation, and analytics features may process PHI solely to provide the contracted services to the Covered Entity, under safeguards consistent with this Agreement and the HIPAA Rules.
Business Associate shall implement and maintain appropriate administrative, physical, and technical safeguards to prevent use or disclosure of PHI other than as provided by this Agreement, including implementing the requirements of the HIPAA Security Rule (45 CFR Part 160 and Part 164, Subparts A and C) with regard to electronic protected health information (ePHI).
(a) Business Associate shall ensure that any subcontractors or agents to whom it provides PHI agree to the same restrictions, conditions, and requirements that apply to Business Associate with respect to such PHI under this Agreement and under 45 CFR 164.504(e).
(b) In accordance with 45 CFR 164.502(e)(1)(ii), Business Associate shall enter into a written agreement with each subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate that contains terms substantially similar to the terms of this Agreement, including terms that require the subcontractor to:
(i) Implement appropriate safeguards to prevent unauthorized use or disclosure of PHI;
(ii) Report to Business Associate any use or disclosure of PHI not provided for in the subcontractor agreement;
(iii) Ensure that any of its agents to whom it provides PHI agree to the same restrictions and conditions;
(iv) Make PHI available for access, amendment, and accounting of disclosures as required by this Agreement;
(v) Return or destroy PHI upon termination of the subcontractor agreement.
(c) Business Associate shall be directly liable to Covered Entity for any breach or violation of this Agreement by its subcontractors or agents.
(d) Business Associate shall take reasonable steps to cure any breach or violation by a subcontractor of which it becomes aware. If such steps are unsuccessful, Business Associate shall terminate the subcontractor agreement, if feasible.
Business Associate shall implement access controls to ensure PHI is accessed only by authorized personnel with a legitimate need to access such information for purposes permitted under this Agreement.
Business Associate shall encrypt PHI at rest and in transit using industry-standard encryption methods that comply with NIST guidelines, including:
(a) Encryption of all PHI stored on servers, databases, and backup systems;
(b) Encryption of all PHI during transmission over public or private networks;
(c) Use of encryption standards approved under the HIPAA Security Rule.
Business Associate shall maintain comprehensive audit logs of all PHI access, modifications, and disclosures, including:
(a) Date and time of access;
(b) User identification;
(c) Type of activity performed;
(d) PHI accessed or disclosed.
Such audit logs shall be maintained for a minimum of six (6) years and shall be made available to Covered Entity upon reasonable request.
(a) Business Associate shall report any security incident or suspected security incident to Covered Entity as required by Section 7 of this Agreement.
(b) Business Associate shall maintain and follow written incident response procedures that include:
(i) Identification and containment of security incidents;
(ii) Assessment of the scope and impact of the incident;
(iii) Notification to appropriate parties;
(iv) Documentation of the incident and response actions;
(v) Post-incident review and corrective action implementation.
(a) Business Associate shall ensure that all members of its workforce who have access to PHI receive appropriate training on the HIPAA Rules and the requirements of this Agreement.
(b) Business Associate shall provide annual HIPAA training updates to its workforce.
(c) Business Associate shall maintain documentation of all training provided.
(a) Access to PHI: Business Associate shall make PHI maintained by Business Associate in a Designated Record Set available to Covered Entity as necessary for Covered Entity to respond to an individual's request for access to PHI in accordance with 45 CFR 164.524. Business Associate shall provide such PHI within ten (10) business days of receiving Covered Entity's request.
(b) Amendment of PHI: Business Associate shall make PHI available for amendment and incorporate any amendments to PHI as directed by Covered Entity in accordance with 45 CFR 164.526. Business Associate shall make such amendments within ten (10) business days of receiving Covered Entity's directive.
(c) Accounting of Disclosures: Business Associate shall document all disclosures of PHI and information related to such disclosures as necessary to provide an accounting of disclosures to Covered Entity in accordance with 45 CFR 164.528. Such documentation shall include:
(i) The date of the disclosure;
(ii) The name and address (if known) of the entity or person who received the PHI;
(iii) A brief description of the PHI disclosed;
(iv) A brief statement of the purpose of the disclosure.
Business Associate shall provide such accounting to Covered Entity within ten (10) business days of receiving Covered Entity's request.
(d) Restriction Requests: If Covered Entity notifies Business Associate that it has agreed to a restriction on use or disclosure of PHI pursuant to 45 CFR 164.522(a), Business Associate shall comply with such restriction.
Business Associate shall make its internal practices, books, and records relating to the use and disclosure of PHI received from, or created or received by Business Associate on behalf of Covered Entity, available to the Secretary of the Department of Health and Human Services for purposes of determining Covered Entity's compliance with the HIPAA Rules. This provision shall remain in effect for six (6) years from the creation or receipt of such PHI.
To the extent Business Associate is to carry out one or more of Covered Entity's obligations under the HIPAA Privacy Rule, Business Associate shall comply with the requirements of the HIPAA Rules that apply to Covered Entity in the performance of such obligation(s).
Upon reasonable request by Covered Entity, Business Associate shall provide information necessary for Covered Entity to include in its Notice of Privacy Practices regarding Business Associate's uses and disclosures of PHI.
Business Associate shall implement the following administrative safeguards:
(a) Designated HIPAA Security Officer responsible for developing, implementing, and maintaining security policies and procedures;
(b) Risk Assessment: Regular security risk assessments (at minimum annually) to identify vulnerabilities and implement appropriate security measures;
(c) Workforce Security: Procedures for authorization and supervision of workforce members who work with ePHI;
(d) Information Access Management: Policies and procedures for granting access to ePHI based on role and need-to-know basis;
(e) Security Awareness Training: Regular workforce training on security threats, policies, and procedures;
(f) Security Incident Procedures: Formal procedures for identifying, reporting, and responding to security incidents;
(g) Contingency Planning: Business continuity and disaster recovery plans including:
(i) Data backup procedures with regular testing;
(ii) Disaster recovery procedures;
(iii) Emergency mode operation procedures;
(iv) Testing and revision procedures.
Business Associate shall implement the following physical safeguards:
(a) Facility Access Controls: Procedures to limit physical access to facilities where ePHI is stored or accessed;
(b) Workstation Security: Policies regarding the proper functions and physical attributes of workstations that access ePHI;
(c) Device and Media Controls: Policies for receipt, removal, disposal, and reuse of hardware and electronic media containing ePHI.
Business Associate shall implement the following technical safeguards:
(a) Access Control:
(i) Unique user identification for all personnel accessing ePHI;
(ii) Emergency access procedures;
(iii) Automatic logoff after period of inactivity;
(iv) Encryption and decryption of ePHI as appropriate.
(b) Audit Controls: Hardware, software, and procedural mechanisms to record and examine activity in systems containing ePHI;
(c) Integrity Controls: Mechanisms to ensure that ePHI is not improperly altered or destroyed;
(d) Transmission Security:
(i) End-to-end encryption for all data transmission;
(ii) Integrity controls to ensure transmitted ePHI is not improperly modified without detection.
Business Associate maintains the following technology infrastructure:
(a) Secure cloud storage with HIPAA-eligible cloud infrastructure;
(b) Multi-factor authentication for all system access;
(c) Automated backup and disaster recovery procedures with:
(i) Daily incremental backups;
(ii) Weekly full backups;
(iii) 30-day backup retention;
(iv) Geographically separate backup storage.
(d) Network security including firewalls, intrusion detection systems, and regular security monitoring;
(e) Regular security audits and vulnerability assessments conducted by independent third parties;
(f) Patch management procedures to ensure timely application of security updates.
Covered Entity shall notify Business Associate of any limitations in its Notice of Privacy Practices, to the extent that such limitation may affect Business Associate's use or disclosure of PHI, and of any changes in, or revocation of, permission by an individual to use or disclose PHI, to the extent that such changes may affect Business Associate's use or disclosure of PHI.
Business Associate shall notify Covered Entity of any breach of unsecured PHI following discovery of such breach, as required by 45 CFR 164.410.
(a) Regulatory Timeline: Business Associate shall provide notification to Covered Entity without unreasonable delay and in no case later than sixty (60) calendar days after discovery of the breach, as required by 45 CFR 164.410(b).
(b) Enhanced Notification: As a best practice, Business Associate commits to provide initial notification to Covered Entity within twenty-four (24) hours of discovery, with complete information to follow as it becomes available.
(c) Definition of Discovery: For purposes of this Section, discovery shall be as defined in Section 3.3 of this Agreement.
The notification provided by Business Associate to Covered Entity shall include, to the extent possible:
(a) Identification of each individual whose unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used, or disclosed during the breach;
(b) A brief description of what happened, including the date of the breach and the date of discovery of the breach, if known;
(c) A description of the types of unsecured PHI involved in the breach (such as full name, Social Security number, date of birth, home address, account number, diagnosis, disability code, or other types of information);
(d) Any steps individuals should take to protect themselves from potential harm resulting from the breach;
(e) A brief description of what Business Associate is doing to investigate the breach, to mitigate harm to individuals, and to protect against further breaches;
(f) Contact information for individuals to ask questions or learn additional information, including a toll-free telephone number, email address, website, or postal address;
(g) Any other information reasonably requested by Covered Entity.
Business Associate shall provide any other available information that Covered Entity is required to include in notification to individuals under 45 CFR 164.404(c) at the time of the initial notification required by this Section or promptly thereafter as information becomes available.
Business Associate shall take reasonable steps to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of PHI by Business Associate in violation of this Agreement.
In addition to breach notification requirements, Business Associate shall report to Covered Entity any use or disclosure of PHI not provided for by this Agreement of which Business Associate becomes aware, including any security incident involving ePHI.
Business Associate shall retain PHI only for as long as necessary to perform the services specified in the underlying service agreement, unless otherwise required by law or as specified in this Section.
Upon termination, cancellation, expiration, or other conclusion of this Agreement, Business Associate shall:
(a) Return to Covered Entity, or if agreed to by Covered Entity, destroy all PHI received from, or created or received by Business Associate on behalf of Covered Entity, that Business Associate still maintains in any form, including all copies thereof;
(b) Retain no copies of such PHI; and
(c) Ensure that all subcontractors and agents to whom Business Associate has disclosed PHI agree to return or destroy all PHI in accordance with this Section.
If return or destruction of PHI is not feasible as determined by Business Associate:
(a) Business Associate shall provide written notification to Covered Entity of the conditions that make return or destruction infeasible;
(b) Covered Entity may, at its sole discretion, either:
(i) Agree that return or destruction is not feasible and authorize Business Associate to retain the PHI; or
(ii) Require Business Associate to take alternative measures that Covered Entity deems appropriate.
(c) If Covered Entity agrees that return or destruction is not feasible, Business Associate shall:
(i) Extend the protections of this Agreement to the retained PHI;
(ii) Limit further uses and disclosures of the retained PHI to those purposes that make the return or destruction of the PHI infeasible;
(iii) Not use or disclose the retained PHI for any other purpose; and
(iv) Return or destroy the retained PHI when it is no longer needed for the purpose that made return or destruction infeasible.
Business Associate shall provide Covered Entity with written certification of the destruction or return of all PHI within thirty (30) days of termination of this Agreement. Such certification shall:
(a) Be signed by an authorized representative of Business Associate;
(b) Specify the date(s) on which the PHI was returned or destroyed;
(c) Describe the method of destruction or return;
(d) Confirm that all copies have been returned or destroyed;
(e) Confirm that all subcontractors and agents have returned or destroyed all PHI as required by this Section.
Notwithstanding the above, if Business Associate is required by law to retain certain PHI, Business Associate shall notify Covered Entity in writing of such requirement and shall:
(a) Maintain such PHI in accordance with the requirements of this Agreement;
(b) Limit use and disclosure of such PHI to the purposes required by law;
(c) Return or destroy such PHI when the legal retention period expires.
Both parties agree to:
(a) Comply with all applicable requirements of the HIPAA Rules and any other applicable federal or state privacy and security laws and regulations;
(b) Cooperate in compliance audits and assessments reasonably requested by the other party;
(c) Maintain current HIPAA compliance certifications and documentation;
(d) Report compliance issues promptly to the other party;
(e) Take prompt corrective action when compliance deficiencies are identified.
(a) Covered Entity may, with reasonable notice and at reasonable times, inspect the facilities, systems, books, and records of Business Associate relating to the use and disclosure of PHI to monitor compliance with this Agreement.
(b) Business Associate shall cooperate with any such inspection and provide reasonable assistance to Covered Entity.
(c) If such inspection reveals non-compliance with this Agreement, Business Associate shall take corrective action as directed by Covered Entity within a reasonable timeframe.
Upon request, but no more than annually unless there is reasonable belief of a breach or violation, Business Associate shall provide Covered Entity with:
(a) A copy of its most recent independent HIPAA compliance report (such as SSAE 18 SOC 2 Type II report or equivalent);
(b) HITRUST certification, if applicable;
(c) Other mutually agreed upon independent standards-based third-party audit reports.
Covered Entity agrees not to re-disclose Business Associate's audit reports to third parties without Business Associate's prior written consent, except as required by law or regulatory authority.
(a) If Covered Entity knows of a pattern of activity or practice of Business Associate that constitutes a material breach or violation of Business Associate's obligations under this Agreement, Covered Entity shall:
(i) Take reasonable steps to cure the breach or end the violation; and
(ii) If such steps are unsuccessful, terminate this Agreement if feasible.
(b) If termination is not feasible, Covered Entity shall report the problem to the Secretary of HHS as required by 45 CFR 164.504(e)(1)(ii).
(c) Business Associate shall similarly monitor its subcontractors and take appropriate action if a pattern of non-compliance is identified.
This Agreement shall be effective as of the date of execution by both parties and shall remain in effect until terminated in accordance with this Section 10, or until all PHI provided by Covered Entity to Business Associate, or created or received by Business Associate on behalf of Covered Entity, is destroyed or returned to Covered Entity, whichever is later.
(a) Material Breach by Business Associate:
(i) Covered Entity may terminate this Agreement immediately upon written notice to Business Associate if Covered Entity determines that Business Associate has violated a material term of this Agreement.
(ii) Before terminating, Covered Entity shall, if feasible, provide Business Associate with written notice of the breach or violation and an opportunity to cure within thirty (30) days or such shorter time as may be required by the circumstances.
(iii) If such steps are unsuccessful, or if immediate termination is necessary to prevent further harm, Covered Entity may terminate this Agreement immediately.
(b) Material Breach by Covered Entity: Business Associate may terminate this Agreement upon thirty (30) days' written notice to Covered Entity if Covered Entity has breached a material term of this Agreement and has not cured such breach within the notice period.
(c) Infeasibility of Termination: If Covered Entity determines that termination of this Agreement is not feasible despite Business Associate's material breach, Covered Entity shall report the problem to the Secretary of HHS as required by 45 CFR 164.504(e)(1)(ii).
Either party may terminate this Agreement without cause upon sixty (60) days' prior written notice to the other party, subject to the provisions of Section 8 regarding return or destruction of PHI.
Upon termination of this Agreement for any reason:
(a) Business Associate shall immediately cease all use and disclosure of PHI, except as necessary to return or destroy PHI in accordance with Section 8;
(b) Business Associate shall comply with all provisions of Section 8 regarding return or destruction of PHI;
(c) The obligations of Business Associate under Sections 5 (Obligations of Business Associate), 7 (Breach Notification), 8 (Data Retention, Return, and Destruction), and 9 (Compliance and Monitoring) shall survive termination of this Agreement;
(d) Neither party shall be relieved of any obligation accrued prior to termination.
The following provisions shall survive termination of this Agreement:
(a) Section 5 (Obligations of Business Associate) - for six (6) years from termination or as required by law;
(b) Section 7 (Breach Notification) - indefinitely for breaches discovered after termination;
(c) Section 8 (Data Retention, Return, and Destruction) - until all obligations are satisfied;
(d) Section 9 (Compliance and Monitoring) - for six (6) years from termination;
(e) Section 11 (Indemnification) - indefinitely;
(f) Section 14 (Dispute Resolution) - for resolution of any disputes arising from this Agreement.
Business Associate agrees to indemnify, defend, and hold harmless Covered Entity, its officers, directors, employees, and agents from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees and costs) arising out of or resulting from:
(a) Business Associate's breach of any provision of this Agreement;
(b) Business Associate's violation of the HIPAA Rules or any other applicable privacy or security law or regulation;
(c) Any unauthorized use or disclosure of PHI by Business Associate, its workforce members, subcontractors, or agents;
(d) Any security incident or breach involving PHI in Business Associate's possession, custody, or control;
(e) Business Associate's failure to comply with any requirement of this Agreement.
Covered Entity agrees to indemnify, defend, and hold harmless Business Associate, its officers, directors, employees, and agents from and against any and all claims, liabilities, damages, losses, costs, and expenses (including reasonable attorneys' fees and costs) arising out of or resulting from:
(a) Covered Entity's breach of any provision of this Agreement;
(b) Covered Entity's failure to obtain any required authorizations or consents from individuals for Business Associate's use or disclosure of PHI;
(c) Any inaccuracy in or incompleteness of PHI provided by Covered Entity to Business Associate.
(a) The party seeking indemnification (the "Indemnified Party") shall promptly notify the other party (the "Indemnifying Party") in writing of any claim for which indemnification is sought.
(b) The Indemnifying Party shall have the right to control the defense and settlement of any such claim, provided that any settlement that adversely affects the Indemnified Party's rights or obligations shall require the Indemnified Party's prior written consent.
(c) The Indemnified Party shall reasonably cooperate with the Indemnifying Party in the defense of any claim.
The indemnification obligations set forth in this Section shall not apply to the extent that any claim, liability, damage, loss, cost, or expense is caused by the gross negligence or willful misconduct of the Indemnified Party.
The parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for compliance with the HIPAA Rules and any other applicable law. Either party may request an amendment to this Agreement by providing written notice to the other party.
(a) Any amendment to this Agreement must be in writing and signed by authorized representatives of both parties.
(b) No amendment shall be effective until executed by both parties.
(c) Either party may request an amendment by providing written notice to the other party, including a description of the proposed amendment and the reason for the amendment.
(d) The parties shall negotiate in good faith to reach agreement on any proposed amendment reasonably necessary to comply with applicable law.
In the event that changes to the HIPAA Rules or other applicable laws require amendments to this Agreement, the parties agree to negotiate such amendments in good faith. Until such amendments are executed, the parties agree to comply with the requirements of the HIPAA Rules as amended.
Any ambiguity in this Agreement shall be resolved in favor of a meaning that permits Covered Entity and Business Associate to comply with the HIPAA Rules and any other applicable privacy and security laws and regulations.
A reference in this Agreement to a section in the HIPAA Rules means the section as in effect or as amended, and for which compliance is required.
If any provision of this Agreement conflicts with applicable law, the parties agree that such provision shall be interpreted, to the extent possible, in a manner that complies with applicable law. If such interpretation is not possible, the conflicting provision shall be deemed modified to the minimum extent necessary to comply with applicable law.
This Agreement contains the entire agreement between the parties with respect to Business Associate's obligations under the HIPAA Rules in connection with PHI. This Agreement does not replace or modify any other agreements between the parties regarding services or other matters.
If any provision of this Agreement is held to be invalid or unenforceable by a court of competent jurisdiction, the remaining provisions shall continue in full force and effect, and such invalid or unenforceable provision shall be reformed or limited only to the extent necessary to make it valid and enforceable.
In the event of any dispute, controversy, or claim arising out of or relating to this Agreement, the parties shall first attempt to resolve the matter through good faith negotiations between authorized representatives of each party.
If the dispute cannot be resolved through good faith negotiations within thirty (30) days, either party may request non-binding mediation. The parties shall mutually select a mediator and share the costs of mediation equally.
If mediation is unsuccessful or if either party declines to participate in mediation, either party may pursue any available legal remedies, subject to the provisions of Section 14.4.
(a) This Agreement shall be governed by and construed in accordance with the laws of the State where Covered Entity is located, without regard to its conflicts of law provisions.
(b) Any legal action arising out of or relating to this Agreement shall be brought exclusively in the state or federal courts located in the jurisdiction where Covered Entity is located, and each party hereby consents to the personal jurisdiction of such courts.
Notwithstanding the above, either party may seek equitable relief (including injunctive relief) in any court of competent jurisdiction to prevent any breach or threatened breach of this Agreement, to prevent disclosure of PHI, or to prevent any other irreparable harm.
All notices, requests, demands, or other communications required or permitted under this Agreement shall be in writing and shall be deemed to have been duly given when:
(a) Delivered personally;
(b) Sent by registered or certified mail, return receipt requested, postage prepaid;
(c) Sent by recognized overnight courier service; or
(d) Sent by email with confirmation of receipt.
Notices shall be sent to the addresses specified in Section 1 of this Agreement or to such other address as either party may designate by written notice to the other party.
This Agreement is intended solely for the benefit of the parties hereto and does not create any rights in any third parties, including but not limited to individuals whose PHI may be disclosed under this Agreement, except as may be required by applicable law.
Neither party may assign or transfer this Agreement or any of its rights or obligations hereunder without the prior written consent of the other party, except that either party may assign this Agreement in connection with a merger, acquisition, or sale of all or substantially all of its assets, provided that the assignee agrees in writing to be bound by the terms of this Agreement.
The failure of either party to enforce any provision of this Agreement shall not be construed as a waiver of such provision or the right to enforce it at a later time. No waiver shall be effective unless in writing and signed by the party against whom the waiver is sought to be enforced.
Business Associate and Covered Entity are independent contractors. Nothing in this Agreement shall be construed to create a partnership, joint venture, agency, employment, or fiduciary relationship between the parties.
Neither party shall be liable for any failure or delay in performing its obligations under this Agreement (other than payment obligations) to the extent that such failure or delay is caused by circumstances beyond the reasonable control of such party, including but not limited to acts of God, war, terrorism, civil unrest, labor disputes, or failures of telecommunications or internet infrastructure.
This Agreement may be executed in counterparts, each of which shall be deemed an original, but all of which together shall constitute one and the same instrument. Electronic signatures shall have the same force and effect as original signatures.
The headings in this Agreement are for convenience only and shall not affect the interpretation of this Agreement.
This Agreement relates only to the parties' obligations with respect to PHI under the HIPAA Rules and does not modify or supersede any other agreements between the parties, including but not limited to any services agreement or master services agreement.
Covered Entity represents and warrants that:
(a) It is a Covered Entity as defined under HIPAA and is subject to the HIPAA Rules;
(b) It has provided Business Associate with its current Notice of Privacy Practices;
(c) It has obtained all necessary authorizations, consents, and permissions from individuals for Business Associate's use and disclosure of PHI as contemplated by this Agreement;
(d) The PHI provided to Business Associate is accurate and complete to the best of Covered Entity's knowledge.
Business Associate represents and warrants that:
(a) It has implemented and maintains appropriate administrative, physical, and technical safeguards to protect PHI in accordance with the HIPAA Security Rule;
(b) It has the necessary expertise, resources, and infrastructure to comply with the requirements of this Agreement;
(c) It has executed appropriate Business Associate Agreements with all subcontractors that will have access to PHI;
(d) It maintains appropriate insurance coverage, including cyber liability insurance and professional liability insurance, in amounts reasonably appropriate for the services provided.
Both parties acknowledge and agree that:
(a) They have read and understand this Agreement;
(b) They have had the opportunity to consult with legal counsel regarding this Agreement;
(c) They will comply with all applicable federal and state laws and regulations regarding the privacy and security of health information;
(d) They understand that violations of the HIPAA Rules may result in civil and criminal penalties, including fines and imprisonment.
By providing your digital signature below, you acknowledge that:
(a) You have read and understood this Business Associate Agreement in its entirety;
(b) You agree to be bound by all terms and conditions herein;
(c) Your digital signature has the same legal effect as a handwritten signature;
(d) This signature will be used for all future Sefton agreements and transactions;
(e) You have the authority to execute this Agreement on behalf of your organization.
COVERED ENTITY (Healthcare Provider):
BUSINESS ASSOCIATE (Sefton Health, Inc. d/b/a Sefton):
Name: Sefton Health, Inc.
D/B/A: Sefton Healthcare Platform
Address: 31 E Newell Avenue, Rutherford, NJ 07070
Phone: (212) 729-7332
Email: admin@sefton.health
Title: HIPAA Compliance Officer
Digital Signature: Sefton Health, Inc.
Date: [Automatically generated upon agreement]