Laserfiche WebLink
34 <br />obligations under this Business Associate Agreement, Covered Entity will <br />take reasonable steps to cure such breach or end such violation. If <br />Covered Entity cannot successfully cure the breach or end the violation, <br />Covered Entity shall terminate the Business Associate Agreement in <br />accordance with Section VI.B if feasible. <br />IV. Electronic Security Provisions <br />A. Introduction. This section applies where Business Associate, on behalf of <br />Covered Entity, performs or assists in the performance of functions and <br />activities that may involve the creation, maintenance, receipt, or <br />transmission of Electronic Protected Health Information. This Section IV <br />along with the other sections of the Business Associate Agreement are (1) <br />intended to meet the requirements of the “business associate” provisions <br />of Security Rule, and (2) govern the terms and conditions under which the <br />Business Associate may create, maintain, receive, and transmit Electronic <br />Protected Health Information on behalf of Covered Entity. In general, <br />Business Associate agrees and intends to act such that (1) Covered Entity <br />can fulfill its responsibilities under HIPAA; (2) Business Associate can fulfill <br />its responsibilities under HIPAA; and (3) Business Associate can fulfill its <br />contractual obligations under this Business Associate Agreement. <br />B. Obligations of Business Associate. In accordance with the Security <br />Rule, Business Associate agrees to: <br />1. Conduct a security risk assessment (in accordance with 45 C.F.R. Section <br />164.308(a)(1)(ii)(A)) and adopt and implement policies and procedures <br />designed to ensure compliance with the Security Rule and this Business <br />Associate Agreement Including identifying a security officer and training <br />personnel. This Paragraph IV.B.1 shall be effective as of the compliance <br />date applicable under the final regulations issued under HITECH that <br />address this requirement. <br />2. Implement administrative, physical and technical safeguards (Including <br />written policies and procedures) that reasonably and appropriately <br />protect the confidentiality, integrity, and availability of the Electronic <br />Protected Health Information that Business Associate creates, <br />maintains, receives, or transmits on behalf of Covered Entity; <br />3. Report to Covered Entity any Security Incident of which Business <br />Associate becomes aware within ten (10) business days of its discovery <br />by the Business Associate; <br />4. Promptly mitigate, to the extent practicable, any harmful effect of a <br />Security Incident that is known to Business Associate; and