skip to main content

HITECH Amendment to Business Associate Contract

This is an amendment to the Business Associate Contract (Contract) between [fill in the name of your practice] (COVERED ENTITY) and [fill in the name of the business associate] (BUSINESS ASSOCIATE) (collectively, the Parties) dated [insert date of original Business Associate Contract].

The Parties are amending the Contract pursuant to Paragraph 11(b) of the Contract, in which they agreed to take such action as is necessary to amend that contract to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).

The purpose of this amendment (Amendment) is to make COVERED ENTITY and BUSINESS ASSOCIATE compliant with the new HIPAA requirements for business associates under the Health Information Technology for Economic and Clinical Health Act (HITECH Act).

Additional Definitions

“Breach” has meaning of that term as defined in §13400 of the HITECH Act (42 USC 17921) and applicable regulations under that section. It includes the unauthorized acquisition, access, use, or disclosure of unsecured PHI that compromises the security or privacy of such information.

“Unsecured PHI” has the meaning of that term as defined at §13402(h) of the HITECH Act 942 USC 17932) and applicable regulations under that section. It includes protected health information (PHI) that is not secured through the use of a technology or methodology specified by the Secretary of the US Department of Health & Human Services under that section.

Additional Contract Terms

1. Obligations of

BUSINESS ASSOCIATE BUSINESS ASSOCIATE agrees to:

A. Comply with the security and privacy provisions of HIPAA made applicable to business associates under the HITECH Act.

B. Ensure that any PHI that BUSINESS ASSOCIATE obtains from COVERED ENTITY, or that BUSINESS ASSOCIATE stores or processes on behalf of COVERED ENTITY, is secured so that it does not qualify as Unsecured PHI.

C. Reimburse COVERED ENTITY for the reasonable costs of providing notice (required by the breach notification regulations under HITECH) of a breach involving PHI described in 1.B that is unsecured.

D. Report to COVERED ENTITY as soon as practicable and in no less than 5 business days any breach of which BUSINESS ASSOCIATE becomes aware.

2. Accounting for Disclosures

Pursuant to the accounting for disclosures provisions of the HITECH Act at 42 USC 17935(c)(3), COVERED ENTITY may provide patients seeking an accounting of disclosures of electronic health records with a list of all business associates acting on COVERED ENTITY’s behalf and their contact information. If COVERED ENTITY does so, and a patient contacts BUSINESS ASSOCIATE directly for an accounting of disclosures, if any, made by BUSINESS ASSOCIATE, BUSINESS ASSOCIATE will provide the required accounting to the patient.

3. Amendment and Construction

A. The Parties agree to take such action as is necessary to amend the Contract from time to time as is necessary to comply with HITECH, HIPAA and the applicable rules and regulations that implement those laws.

B. Interpretation: Any ambiguity in the Contract, this amendment or prior amendments to the Contract shall be resolved to permit the COVERED ENTITY to comply with HITECH, HIPAA and the applicable rules and regulations that implement those laws.

C. If there are any conflicts between the terms of the Contract, this amendment or prior amendments to the Contract, the terms of this amendment control.

In Witness Whereof, BUSINESS ASSOCIATE and COVERED ENTITY have caused this Amendment to be signed and delivered by their duly authorized representatives, as of the date set forth above.

BUSINESS ASSOCIATE:

______________________________

Signature

_______________________________________________

Print Name and Title

_______________

Date

COVERED ENTITY:

______________________________

Signature

 

_______________________________________________

Print Name and Title

_______________

Date 

Date created: 2010