ProveTripNEMT

Create an organization

You become the owner. Drivers, dispatchers and billers get added afterwards, and your account is ready the moment you accept the agreement below.

Business associate agreement

Required before your members’ records can be held here. Scroll to the end to accept.

# Business Associate Agreement This Business Associate Agreement (the "BAA") is entered into as of the date it is accepted electronically, by and between **Vince Systems LLC** (formerly Insta Perf LLC), an Iowa limited liability company, operating the ProveTrip service ("Business Associate"), and the organization accepting this BAA ("Covered Entity"), in accordance with the meaning given to those terms at 45 CFR § 160.103. In this BAA, Covered Entity and Business Associate are each a "Party" and, collectively, are the "Parties". ## Background 1. Covered Entity is either a "covered entity" or a "business associate" of a covered entity as each is defined under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191, as amended by the HITECH Act and the related regulations promulgated by HHS (collectively, "HIPAA"), and as such is required to comply with HIPAA's provisions regarding the confidentiality and privacy of Protected Health Information. 2. The Parties have entered into or will enter into one or more agreements under which Business Associate provides or will provide specified services to Covered Entity (collectively, the "Agreement"), being the provision of the ProveTrip software service for recording non-emergency medical transport trips and reconciling payment for them. 3. In providing services pursuant to the Agreement, Business Associate will have access to Protected Health Information. 4. By providing the services pursuant to the Agreement, Business Associate will become a "business associate" of Covered Entity as that term is defined under HIPAA. 5. Both Parties are committed to complying with all federal and state laws governing the confidentiality and privacy of health information. ## 1. Definitions Capitalized terms used but not defined in this BAA have the meaning given to them by HIPAA. For clarity: - **"Breach"** has the meaning given at 45 CFR § 164.402. - **"Designated Record Set"** has the meaning given at 45 CFR § 164.501. - **"Electronic Protected Health Information" ("ePHI")** has the meaning given at 45 CFR § 160.103, limited to information created, received, maintained or transmitted by Business Associate on behalf of Covered Entity. - **"HITECH Act"** means the Health Information Technology for Economic and Clinical Health Act, Public Law 111-005. - **"Individual"** has the meaning given at 45 CFR § 160.103 and includes a person who qualifies as a personal representative under 45 CFR § 164.502(g). - **"Protected Health Information" ("PHI")** has the meaning given at 45 CFR § 160.103, limited to information created, received, maintained or transmitted by Business Associate on behalf of Covered Entity. - **"Required By Law"** has the meaning given at 45 CFR § 164.103. - **"Security Incident"** has the meaning given at 45 CFR § 164.304. - **"Unsecured PHI"** has the meaning given at 45 CFR § 164.402. ## 2. Use and Disclosure of PHI Business Associate may use and disclose PHI only as follows: (a) as necessary to perform the services described in the Agreement; (b) as Required By Law; (c) for the proper management and administration of Business Associate, or to carry out its legal responsibilities, provided that any disclosure for such purposes is either Required By Law or made only where Business Associate obtains reasonable assurances from the person to whom the PHI is disclosed that it will be held confidentially and used or further disclosed only as Required By Law or for the purpose for which it was disclosed, and that the person will notify Business Associate of any instance of which it is aware in which the confidentiality of the information has been breached; and (d) to provide data aggregation services relating to the health care operations of Covered Entity, as permitted by 45 CFR § 164.504(e)(2)(i)(B). Business Associate will not use or disclose PHI in any manner that would constitute a violation of HIPAA if so used or disclosed by Covered Entity, and will not sell PHI or use or disclose PHI for marketing or fundraising purposes. Business Associate will make reasonable efforts to use, disclose and request only the minimum necessary PHI to accomplish the intended purpose, consistent with 45 CFR § 164.502(b). ## 3. Safeguards Against Misuse of PHI Business Associate will use appropriate administrative, physical and technical safeguards to prevent the use or disclosure of PHI other than as permitted by this BAA, and will comply with the Security Rule at 45 CFR Part 164, Subpart C, with respect to ePHI. Without limiting the foregoing, Business Associate: (a) isolates each Covered Entity's records from every other customer's records, and enforces that isolation in the database itself rather than by application logic alone; (b) restricts access to PHI to those of its workforce who require it, and does not provide its own administrative staff with any means of reading a Covered Entity's member records through its administrative console; (c) records access to member records in an append-only audit log available to Covered Entity; and (d) encrypts PHI in transit and at rest. ## 4. Reporting Disclosures of PHI and Security Incidents Business Associate will report to Covered Entity any use or disclosure of PHI not permitted by this BAA, and any Security Incident of which it becomes aware, without unreasonable delay and in any event within five (5) business days of becoming aware of it. The Parties acknowledge that this section constitutes notice of the ongoing existence and occurrence of attempted but unsuccessful Security Incidents — such as pings and other broadcast attacks on a firewall, port scans, unsuccessful log-on attempts, and denial of service attacks — for which no additional notice will be required. ## 5. Reporting Breaches of Unsecured PHI Business Associate will notify Covered Entity of any Breach of Unsecured PHI without unreasonable delay and in no case later than twenty (20) calendar days after discovery of the Breach. A Breach is treated as discovered on the first day on which it is known, or by exercising reasonable diligence would have been known, to Business Associate. The notification will include, to the extent known at the time and supplemented as further information becomes available: (a) the identification of each Individual whose Unsecured PHI has been, or is reasonably believed to have been, accessed, acquired, used or disclosed; (b) a description of what happened, including the date of the Breach and the date of its discovery; (c) a description of the types of Unsecured PHI involved; (d) a description of what Business Associate is doing to investigate, to mitigate harm, and to protect against further breaches; and (e) a contact at Business Associate able to answer questions. Business Associate will cooperate with Covered Entity in meeting Covered Entity's obligations under 45 CFR §§ 164.404 through 164.410. ## 6. Mitigation of Disclosures of PHI Business Associate will mitigate, to the extent practicable, any harmful effect known to it of a use or disclosure of PHI by Business Associate in violation of this BAA. ## 7. Agreements with Agents or Subcontractors Business Associate will ensure that any subcontractor that creates, receives, maintains or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as protective as those that apply to Business Associate under this BAA, as required by 45 CFR § 164.502(e)(1)(ii) and § 164.308(b)(2). Business Associate's hosting infrastructure is provided by Amazon Web Services under an executed AWS Business Associate Addendum. Business Associate does not transmit PHI by text message or by electronic mail. Messages sent to a Covered Entity's drivers state only the number of trips assigned and their scheduled times; they name no Individual and contain no information about any Individual's condition, treatment or destination. ## 8. Audit Report Upon written request, Business Associate will provide Covered Entity with a summary of its then-current information security practices relevant to the services, and will reasonably cooperate with Covered Entity's inquiries regarding Business Associate's compliance with this BAA. ## 9. Access to PHI by Individuals Business Associate will, within ten (10) business days after written request by Covered Entity, make available to Covered Entity PHI in a Designated Record Set held by Business Associate as necessary for Covered Entity to satisfy its obligations under 45 CFR § 164.524. Where an Individual makes such a request directly to Business Associate, Business Associate will forward it to Covered Entity, which is responsible for responding. ## 10. Amendment of PHI Business Associate will, within ten (10) business days after written request by Covered Entity, make available PHI in a Designated Record Set for amendment, and incorporate any amendment to that PHI, as necessary for Covered Entity to satisfy its obligations under 45 CFR § 164.526. ## 11. Accounting of Disclosures Business Associate will document disclosures of PHI and information related to those disclosures as would be required for Covered Entity to respond to a request for an accounting of disclosures under 45 CFR § 164.528, and will, within ten (10) business days after written request by Covered Entity, make that information available to Covered Entity. ## 12. Availability of Books and Records Business Associate will make its internal practices, books and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining Covered Entity's compliance with HIPAA. ## 13. Responsibilities of Covered Entity Covered Entity will: (a) notify Business Associate of any limitation in its notice of privacy practices, of any changes in or revocation of an Individual's permission to use or disclose PHI, and of any restriction on the use or disclosure of PHI that Covered Entity has agreed to or is required to abide by, in each case to the extent it affects Business Associate's use or disclosure of PHI; (b) not request Business Associate to use or disclose PHI in any manner that would not be permissible under HIPAA if done by Covered Entity; and (c) be solely responsible for the accuracy and lawfulness of the PHI it, or those acting on its behalf, enters into the service, and for managing which of its own workforce have access to it. ## 14. Data Ownership As between the Parties, all PHI and all records created in the service on behalf of Covered Entity remain the property of Covered Entity. Business Associate acquires no ownership interest in them and no right to use them other than as set out in this BAA and the Agreement. Covered Entity may export its records at any time while its account is open. ## 15. Term and Termination This BAA takes effect on the date it is accepted and continues until the Agreement ends or it is terminated as provided below. Covered Entity may terminate this BAA and the Agreement if Business Associate materially breaches this BAA and fails to cure the breach within thirty (30) days of written notice, or immediately if cure is not possible. Upon termination, Business Associate will, if feasible, return or destroy all PHI it maintains on behalf of Covered Entity and retain no copies. Where return or destruction is not feasible, Business Associate will extend the protections of this BAA to that PHI and limit further use and disclosure to those purposes that make return or destruction infeasible, for so long as it is retained. Covered Entity may request an export of its records for a period of thirty (30) days after termination. The obligations of Business Associate under this section survive termination. ## 16. Effect of BAA To the extent this BAA conflicts with any other term of the Agreement in respect of PHI, this BAA controls. In all other respects the Agreement remains in effect. Any ambiguity in this BAA will be resolved in favour of a meaning that permits the Parties to comply with HIPAA. ## 17. Regulatory References A reference in this BAA to a section of HIPAA means that section as in effect or as amended, and for which compliance is required. ## 18. Notices Notices to Business Associate go to: > Vince Systems LLC > 3930 Westwind Ct, Waukee, IA 50263 > vince@vincesystems.com Notices to Covered Entity go to the address and email held on its account, which Covered Entity is responsible for keeping current. ## 19. Amendments and Waiver This BAA may not be amended except in writing. The Parties agree to take such action as is necessary to amend this BAA from time to time as is necessary for the Parties to comply with HIPAA. No failure or delay in exercising a right under this BAA operates as a waiver of it. ## 20. HITECH Act Compliance Business Associate acknowledges that it is directly subject to those provisions of the HITECH Act and the HIPAA Security and Privacy Rules that apply to business associates, and agrees to comply with them. --- This agreement is governed by the laws of the State of Iowa. Accepted electronically by the person named at acceptance, on behalf of Covered Entity, who represents that they are authorised to bind it. The version accepted, the full text shown, a SHA-256 hash of that text, the acceptor's name, title and email, the IP address and the time of acceptance are recorded by Business Associate.

Already set up? Sign in

← Back to provetrip.com