This agreement governs the handling of protected health information exchanged between Compass Healthcare LLC and the healthcare providers it serves, in accordance with HIPAA and the HITECH Act.
This Business Associate Agreement ("Agreement") is entered into between a covered entity ("Covered Entity") and Compass Healthcare LLC ("Business Associate"). It takes effect on the date the parties execute it (the "Effective Date").
Business Associate provides services to Covered Entity — which may include medical billing, revenue cycle management, IT support, data collection, and the Clinical Outcome platform — that involve the creation, receipt, maintenance, or transmission of Protected Health Information ("PHI"). The parties enter into this Agreement to comply with the HIPAA Privacy, Security, and Breach Notification Rules.
Capitalized terms used but not defined here have the meaning given in the HIPAA Rules (45 CFR Parts 160 and 164).
Business Associate agrees to:
Business Associate may use or disclose PHI only:
Business Associate will make reasonable efforts to use, disclose, and request only the minimum necessary PHI to accomplish the intended purpose.
Consistent with the HIPAA Security Rule, Business Associate will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of ePHI. These include, where applicable, encryption of data in transit and at rest, role-based access controls, audit logging, and workforce security training.
In accordance with 45 CFR §§164.308(b)(2) and 164.502(e)(1)(ii), Business Associate will require any subcontractor that creates, receives, maintains, or transmits PHI on its behalf to agree in writing to restrictions and conditions at least as protective as those in this Agreement.
Business Associate will report to Covered Entity any Breach of unsecured PHI without unreasonable delay and no later than 3 calendar days after discovery. The report will include, to the extent known, the individuals affected, a description of what happened, the types of information involved, and the steps taken to mitigate and prevent recurrence.
This Agreement is effective as of the Effective Date and continues until all PHI is returned or destroyed, or protections are extended to retained PHI. Covered Entity may terminate this Agreement if Business Associate materially breaches it and fails to cure within 30 days of written notice.
Upon termination, Business Associate will, where feasible, return or destroy all PHI received from, or created or received on behalf of, Covered Entity. Where return or destruction is not feasible, Business Associate will extend the protections of this Agreement to such PHI and limit further uses and disclosures.