Laserfiche WebLink
DocuSign Envelope ID: 26BOC939-3E65-4374-8EBE-308B214EB5C7 <br />EXHIBIT D <br />BUSINESS ASSOCIATE AGREEMENT ADDENDUM <br />THIS BUSINESS ASSOCIATE AGREEMENT ADDENDUM ("Addendum") to <br />be effective as of April 6, 2020 (the "Effective Date"), by and between the City of San <br />Leandro ("Covered Entity") and East Bay Innovations (Business Associate"). <br />WHEREAS, Business Associate performs services ("Services") on behalf of Covered <br />Entity pursuant to that certain one or more services agreement the parties have entered into, <br />titled Consulting Services Agreement, as applicable ("Underlying Agreement"), which <br />Services involve the use and/or disclosure of Protected Health Information (defined below); and <br />WHEREAS, the parties desire to enter into this Addendum in order to comply with the <br />business associate agreement requirements of the Health Insurance Portability and <br />Accountability Act of 1996 ("HIPAA") and its implementing privacy, security, breach <br />notification and enforcement rules at 45 C.F.R. Parts 160 and 164 ("HIPAA Rules"), the <br />applicable provisions of the Health Information and Technology for Economic and Clinical <br />Health Act of 2009 ("HITECH") and any future implementing regulations and guidance issued <br />by the Secretary. <br />NOW, THEREFORE, the parties do hereby agree as follows: <br />1. Definitions. Capitalized terms not otherwise defined in this Addendum shall have the <br />same meaning as those terms in the Privacy Rule and the Security Rule. <br />a) "Breach" when capitalized, "Breach" shall have the meaning set forth in 45 CFR <br />§ 164.402 (including all of its subsections); with respect to all other uses of the <br />word "breach" in this Addendum, the word shall have its ordinary contract <br />meaning. <br />b) "Electronic Protected Health Information" or "EPHI" shall have the same <br />meaning as the term "electronic protected health information" in 45 CFR § <br />160.103, limited to information that Business Associate creates, accesses or <br />receives on behalf of Covered Entity. <br />C) "HITECH Act" shall mean the Health Information Technology for Economic <br />and Clinical Health Act, found in Title XIII of the American Recovery and <br />Reinvestment Act of 2009, effective February 17, 2009. <br />d) "Protected Health Information" or "PHI" shall have the meaning set forth in <br />the Privacy Rule, limited to information that Business Associate creates, accesses <br />or receives on behalf of Covered Entity. PHI includes EPHI. <br />Revised <br />5/21/2020 <br />