Loading...
Ordinance No. 13,781ORDINANCE NO. 13,781 AN ORDINANCE OF THE CITY COUNCIL OF THE CITY OF BAYTOWN, TEXAS, AUTHORIZING A CONTRACT WITH THE TEXAS DEPARTMENT OF STATE HEALTH SERVICES FOR ONLINE COMPUTER ACCESS TO THE VITAL EVENT ELECTRONIC REGISTRATION SYSTEM FOR THE PURPOSE OF ISSUING INDIVIDUAL BIRTH CERTIFICATES; AUTHORIZING PAYMENT IN AN AMOUNT NOT TO EXCEED TEN THOUSAND AND N01100 DOLLARS ($10,000.00); MAKING OTHER PROVISIONS RELATED THERETO; AND PROVIDING FOR THE EFFECTIVE DATE THEREOF. ************************************************************************************* BE IT ORDAINED BY THE CITY COUNCIL OF THE CITY OF BAYTOWN, TEXAS: Section 1: That the City Council of the City of Baytown, Texas, hereby authorizes the City Manager to execute a contract with the Department of State Health Services for online computer access to its Vital Event Electronic Registration System for the purpose of issuing individual birth certificates. A copy of said agreement is attached hereto as Exhibit "A' and incorporated herein for all intents and purposes. Section 2: That the City Council of the City of Baytown hereby authorizes payment in an amount not to exceed TEN THOUSAND AND N01100 DOLLARS ($10,000.00) pursuant to the Agreement authorized in Section 1 hereof. Section 3: That the City Manager is hereby granted general authority to approve any change order involving a decrease or an increase in costs of FIFTY THOUSAND AND N01100 DOLLARS ($50,000.00) or less; however, the original contract price may not be increased by more than twenty-five percent (25%) or decreased by more than twenty-five percent (25%) without the consent of the contractor to such decrease. Section 4: This ordinance shall take effect immediately from and after its passage by the City Council of the City of Baytown. INTRODUCED, READ and PASSED by the affirmative vote of the City Council of the City of Baytown this the 24th day of May, 2018. ATT T: LETICIA BRYSCH, Ci Clerk APPROVED AS TO FORM: I ACIO RAMIREZ, SR., ty ttorney ALVARADO, Mayor Pro Tem ' `•.cobfs0lUegal\Karen\Files'.City CouncihOrdinances\201 MMay 24'+VitalRecordsContractwithState.doc EXHIBIT "A" Contract Number: HHSREV 100000793 DEPARTMENT OF STATE HEALTH SERVICES Contract number HHSREV 100000793 (the "Contract'), is entered into by Department of State Health Services ("DSHS") Vital Statistics Section and City of Baytown ("Contractor"). DSHS and Contractor are collectively referred to herein as the "Parties." I. Purpose of the Contract. DSHS agrees to provide access to the DSHS Vital Event Electronic Registration System for the purpose of issuing individual birth certificates. II. Term of the Contract. This Contract will begin on September 1, 2018, and end on August 31, 2023. III. Authority. The Parties enter into this Contract under the authority of Texas Health and Safety Code Chapter 191 and Texas Government Code Chapter 791. IV. Statement of Work. A. DSHS agrees to provide on-line computer services in support of Contractor from 7:00 a.m. to 6:00 p.m. (CST) Monday through Friday, except holidays. In the event of an emergency or computer application error, DSHS may temporarily suspend services without advance notice. B. Contractor may search DSHS databases, locate data, and issue Certifications of Birth to authorized individuals requesting such data. The certifications will be in a format formally approved by DSHS. Contractor will take reasonable efforts to ensure use of the DSHS Vital Event Electronic Registration System is not abused by its staff. Abuse of the access to confidential information in the DSHS Vital Event Electronic Registration System maybe cause for termination of this Contract in accordance with Section W.K. C. Contractor will acquire the necessary data processing equipment, communications, hardware or software, and purchase "bank note" paper, as specified by DSHS. DSHS will assist in connection of the equipment, furnish software program and provide technical assistance, if necessary. D. Contractor will complete the DSHS Vital Event Electronic Registration System registration forms as specified by DSHS. Contractor will remain in compliance with any requirements specified by DSHS for accessing the DSHS Vital Event Electronic Registration System. Contractor will not be required to pay an additional fee pursuant to this Subsection. E. Contractor acknowledges that records may not be located in the searching process instituted by Contractor, or records which are located may have errors due to: VSS Remote Binh Access Page I Contract Number: HHSREV 100000793 1. Normal key -entry errors in spellings; 2. Accidental failure on the part of the DSHS to update a file for an amendment or paternity determination; and 3. The event year does not exist on the system. F. Contractor will notify DSHS in writing, at least monthly of errors or suspected errors that exist on the database information. G. Contractor is to maintain an inventory control and account for each document produced on "bank note" paper, including voided documents. H. Contractor will issue Certificates of Birth utilizing remote access to the DSHS system in conformance with Health and Safety Code Chapters 191, 192 and 195, as well as 25 Tex. Admin. Code Chapter 181. I. The Parties are required to comply with all applicable state and federal laws relating to the privacy and confidentiality of this data and records, which includes Texas Government Code Section 552.115. J. The Parties will use confidential records and information obtained under this Contract only for purposes as described in this Contract and as otherwise allowed by law. V. Fees. Contractor agrees to pay DSHS ONE DOLLAR AND EIGHTY-THREE CENTS ($1.83) for each Certification of Vital Record printed as a result of searches of the database. Contractor agrees to charge the same base search fee for a birth certificate as DSHS. Additional fees may only be charged as authorized by Texas Health and Safety Code Chapter 191 and 25 Tex. Admin. Code Chapter 181. Vl. Billie . A. DSHS will send an itemized billing to Contractor on a monthly basis for each Certification of Birth printed. This billing will be sent through the U.S. Postal Service to the Contractor at: Name: City of Baytown Address: 2401 Market Street Baytown, TX 77520 B. Contractor will direct any billing inquiries either by phone to 512-776-7206 or email to vsubusinessservices(@dshs.state.tx.us. VSS Remote Binh Access Page 2 Contract Number: HHSREV 100000793 VII. Payment Method. A. Contractor will remit payment to DSHS within thirty days after a billing is received by them. Payment by the Contractor will be considered made on the date postmarked. B. Contractor will send payments to DSHS at: Texas Department of State Health Services Cash Receipts Branch MC 2096 P.O. Box 149347 Austin, TX 78714-9347 C. Contractor will make payment to DSHS out of its current revenues. VIII. Representatives. The following will act as the Representative authorized to administer activities under this Contract on behalf of their respective Party. City of Baytown City of Baytown City Clerk's Office Attn: Leticia Brysch 2401 Market Street Baytown, TX 77520 Phone: (281) 420-6504 Email: leticia.brysch@baytown.org DSHS Texas Department of State Health Services Contract Management Section Attn: Kathleen Uptmor Mail Code 1990 P.O. Box 149347 Austin, TX 78714-9347 Phone: (512) 776-3945 Email: Kathleen. IX. General Terms and Conditions. A. Governing Law. Regarding all issues related to this Contract's formation, performance, interpretation, and any issues that may arise in any dispute between the parties, the Contract will be governed by and construed in accordance with the Iaws of the State of Texas. B. Amendment. This Contract may be modified by written amendment signed by the Parties. C. Confidentiality, The Parties are required to comply with all applicable state and federal laws relating to the privacy and confidentiality of records that contain Personal Identifying Information (PIi) or Personally Sensitive Information (PSI) or other information or records made confidential by law, including Tex. Bus. & Comm. Code Section 521.002. The attached Data Use Agreement (Attachment A) applies to this Contract. VSS Remote Binh Access Page 3 Contract Number: HHSREV 100000793 D. Exchange of Personal Identifying Information. This Contract concerns personal identifying information. Except as prohibited by other law, Contractor and DSHS may exchange PII without consent, in accordance with Chapter 191 of the Health and Safety Code. E. Records Retention. DSHS will retain records in accordance with DSHS State of Texas Records Retention Schedule at http: www.dshs.texas.gov records/schedules.shtm, Department Rules and other applicable state and federal statutes and regulations governing medical, mental health, and substance abuse information. F. Severability. If any provision of this Contract is construed to be illegal or invalid, the illegal or invalid provision will be deemed stricken and deleted to the same extent and effect as if never incorporated, but all other provisions will continue. G. Notice. Any notice required or permitted to be given under this Contract will be in writing and sent to the respective Party's Representative in Section VIII. Notice will be deemed to have been received by a Party on the third business day after the date on which it was mailed to the Party at the address specified in writing by the Party to the other Party, or, if sent by certified mail, on the date of receipt. H. Waiver. Acceptance by either Party of partial performance or failure to complain of any action, non -action or default under this Contract will not constitute a waiver of either Party's rights under the Contract. 1. Assignment. Neither DSHS nor Contractor will transfer, assign, or sell its interest, in whole or in part, in this Contract without prior written consent by both Parties. J. Suspension of Services Under This Contract. In the event of an emergency or information technology system failure, DSHS may temporarily suspend services without advance notice. Use of services for purposes inconsistent with applicable law may also result in a suspension of services. IC Termination. 1. Convenience. This Contract may be terminated by mutual agreement of the Parties. Either Party may terminate this Contract without cause by giving 30 days written notice of its intent to terminate to the non -terminating Party. 2. Cause. This Contract may be terminated for cause by either Party for breach or failure to perform an essential requirement of the Contract. Use of services for purposes inconsistent with applicable law may be cause for Contract termination. 3. Notice of Termination. Written notice may be sent by any method that provides verification of receipt, which will be calculated from the date of receipt by the non - terminating Party's Representative provided in Section VIII. VSS Remote Seth Access Page 4 Contract Number: HHSREV100000793 4. Equitable Settlement. At the end of the Term of this Contract or termination as provided for in this Section, the Parties will equitably settle their respective accrued interests or obligations incurred prior to termination. By signing below, the Parties agree that this Contract constitutes the entire legal and binding agreement between them. The Parties acknowledge that they have read the Contract and agree to its terns, and that the persons whose signatures appear below have the authority to execute this Contract on behalf of their respective Party. DEPARTMENT OF STATE HEALTH SERVICES CITY OF BAYTOWN 1x6'lztd'6_ A�imp Manda Hall, M.D. Rick Davis Associate Commissioner City Manager Department of State Health Services City of Baytown 11,311g Date Date THE FOLLOWING ATTACHMENTS ARE ATTACHED AND INCORPORATED AS PART OF THE CONTRACT HHSREV100000793: ATTACHMENT A- DATA USE AGREEMENT VSS Remote Both Access Page 5 ATTACHMENT A — DATA USE AGREEMENT DATA USE AGREEMENT BETWEEN THE TEXAS HEALTH AND HUMAN SERVICES ENTERPRISE AND CITY OF BAYTOWN ("CONTRACTOR") This Data Use Agreement ("DUA") is incorporated into System Agency Contract No. HHSREV 100000793 (the "Base Contract'j between the Texas Department of State Health Services ("System Agency') and City of Baytown ('Contractor"). ARTICLE 1 -PURPOSE; APPLICABILITY; ORDER OF PRECEDENCE ATTACHMENT 1. The purpose of this DUA is to facilitate creation, receipt, maintenance, use, disclosure or access to Confidential Information with Contractor, and describe Contractor's rights and obligations with respect to the Confidential Information and the limited purposes for which the Contractor may create, receive, maintain, use, disclose or have access to Confidential Information. 45 CFR 164.504(e)(1)-(3). This DUA also describes System Agency's remedies in the event of Contractor's noncompliance with its obligations under this DUA. This DUA applies to both Business Associates and contractors who are not Business Associates who create, receive, maintain, use, disclose or have access to Confidential Information on behalf of System Agency, its programs or clients as described in the Base Contract. As of the Effective Date of the Contract, if any provision of the Base Contract, including any General Provisions or Uniform Terns and Conditions, conflicts with this DUA, this DUA controls. ARTICLE 2. DEFINITIONS For the purposes of this DUA, capitalized, underlined terms have the meanings set forth in the following; Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 (42 U.S.C. §1320d, et seq.) and regulations thereunder in 45 CFR Paris 160 and 164, including all amendments, regulations and guidance issued thereafter, The Social Security Act, including Section 1137 (42 U.S.C. §§ 1320b-7), Title XVI of the Act; The Privacy Act of 1974, as amended by the Computer Matching and Privacy Protection Act of 1988, 5 U.S.C. § 552a and regulations and guidance thereunder, Internal Revenue Code, Title 26 of the United States Code and regulations and publications adopted under that code, including IRS Publication 1075; OMB Memorandum 07-18; Texas Business and Commerce Code Ch. 521; Texas Government Code, Ch. 552, and Texas Government Code §2054.1125. In addition, the following terms in this DUA are defined as follows: "Authorized Purpose' means the specific purpose or purposes described in the Scope of Work of the Base Contract for Contractor to fulfill its obligations under the Base Contract, or any other purpose expressly authorized by System Agency in writing in advance. "Authorized User" means a Person: (1) Who is authorized to create, receive, maintain, have access to, process, view, handle, examine, interpret, or analyze Confidential Information pursuant to this DUA; (2) For whom Contractor warrants and represents has a demonstrable need to create, receive, maintain, use, disclose or have access to the Confidential Information; and System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 GOVERNMENTAL ENTITY VERSION System Agency Contract No.HHSREV 100000793 (3) Who has agreed in writing to be bound by the disclosure and use limitations pertaining to the Confidential Information as required by this DUA. "Confidential Information" means any communication or record (whether oral, written, electronically stored or transmitted, or in any other form) provided to or made available to Contractor or that Contractor may create, receive, maintain, use, disclose or have access to on behalf of System Agency that consists of or includes any or all of the following: (1) Client Information; (2) Protected Health Information in any form including without limitation, Electronic Protected Health Information or Unsecured Protected Health Information: (3) Sensitive Pe sonal Information defined by Texas Business and Commerce Code Ch. 521; (4) Federal Tax Information• (5) Personally Identifiable Information; (6) Social Security Administration Data, including, without limitation, Medicaid information; (7) All privileged work product; (8) All information designated as confidential under the constitution and laws of the State of Texas and of the United States, including the Texas Health & Safety Code and the Texas Public Information Act, Texas Government Code, Chapter 552. "Legally Authorized Representative" of the Individual, as defined by Texas law, including as provided in 45 CFR 435.923 (Medicaid); 45 CFR 164.502(gxl) (HIPAA); Tex. Occ. Code § 151.002(6); Tex. H. & S. Code § 166.164; Estates Code Ch. 752 and Texas Prob. Code § 3. ARTICLE 3.CONTRACTOR'S DUTIES REGARDING CONFIDENTIAL INFORMATION Section 3.01 Obligations of Contractor Contractor agrees that: (A) Contractor will exercise reasonable care and no less than the same degree of care Contractor uses to protect its own confidential, proprietary and trade secret information to prevent any portion of the Confidential Information from being used in a manner that is not expressly an Authorized Purpose under this DUA or as Required by Law. 45 CFR 164.502(b)(1); 45 CFR 164.514(d) (B) Contractor will not, without System Agency's prior written consent, disclose or allow access to any portion of the Confidential Information to any Person or other entity, other than Authorized User's Workforce or Subcontractors of Contractor who have completed training in confidentiality, privacy, security and the importance of promptly reporting any Event or Breach to Contractor's management, to carry out the Authorized Purpose or as Required by Law. System Agency, at its election, may assist Contractor in training and education on specific or unique System Agency processes, systems or requirements. Contractor will produce evidence of completed training to System Agency upon request. 45 C.F.R. 164.308(a)(5)(i); Texas Healtir & Safety Code §181.101 (C) Contractor will establish, implement and maintain appropriate sanctions against any member of its Workforce or Subcontractor who fails to comply with this DUA, the Base Contract or applicable law. Contractor will maintain evidence of sanctions and produce it to System Agency upon request.45 C.F.R. 164.308(a)(1)ri)(C); 164.530(e); 164.410(b); 164.530(b)(1) System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 2 of 11 System Agency Contract No, HHSREV100000793 (D) Contractor will not, without prior written approval of System Agency, disclose or provide access to any Confidential Information on the basis that such act is Required by Law without notifying System Agency so that System Agency may have the opportunity to object to the disclosure or access and seek appropriate relief. If System Agency objects to such disclosure or access, Contractor will refrain from disclosing or providing access to the Confidential Information until System Agency has exhausted all alternatives for relief. 45 CFR 164.504(e)(2)(ii)(A) (E) Contractor will not attempt to re -identify or further identify Confidential Information or De -identified Information, or attempt to contact any Individuals whose records are contained in the Confidential Information, except for an Authorized Purpose, without express written authorization from System Agency or as expressly permitted by the Base Contract. 45 CFR 164.502(d)(2)r) and (U) Contractor will not engage in prohibited marketing or sale of Confidential Information. 45 CFR 164.501, 164.508(a) (3) and (4); Texas Healdo & Safety Code Cls. 18L002 (F) Contractor will not permit, or enter into any agreement with a Subcontractor to, create, receive, maintain, use, disclose, have access to or transmit Confidential Information on behalf of Contractor without requiring that Subcontractor first execute the Form Subcontractor Agreement, Attachment 1, which ensures that the Subcontractor will comply with the identical terms, conditions, safeguards and restrictions as contained in this DUA for PHI and any other relevant Confidential Information and which permits more strict limitations; and 45 CFR 164.502(e)(1)(1)(ii); 164.504(e)(1)r) and (2) (G) Contractor is directly responsible for compliance with, and enforcement of, all conditions for creation, maintenance, use, disclosure, transmission and Destruction of Confidential Information and the acts or omissions of Subcontractors as may be reasonably necessary to prevent unauthorized use. 45 CFR 164.504(e)(5); 42 CFR 431.300, et seq. (H) If Contractor maintains PHI in a Designated Record Set. Contractor will make PHI available to System Agency in a Designated Record Set or, as directed by System Agency, provide PHI to the Individual. or Legally Authorized Reoresenta&e of the Individual who is requesting PHI in compliance with the requirements of the HIPAA Privacy Regulations. Contractor will make other Confidential Information in Contractor's possession available pursuant to the requirements of HIPAA or other applicable law upon a determination of a Breach of Unsecured PHI as defined in HIPAA. 45 CFR 164524and 164.504(e)(2)(ii)(E) (1) Contractor will make PHI as required by HIPAA available to System Agency for amendment and incorporate any amendments to this information that System Agency directs or agrees to pursuant to the HIPAA. 45 CFR 164.504(e)(2)(ii)(E) and (F) (J) Contractor will document and make available to System Agency the PHI required to provide access, an accounting of disclosures or amendment in compliance with the requirements of the HIPAA Privacy Regulations. 45 CFR 164504(e)(2)(ii)(G) and 164.528 (K) If Contractor receives a request for access, amendment or accounting of PHI by any Individual subject to this DUA, it will promptly forward the request to System Agency; however, if it would violate HIPAA to forward the request, Contractor will promptly notify of the request and of Contractor's response. Unless Contractor is prohibited by law from forwarding a request, System Agency will respond to all such requests, unless System Agency has given prior written consent for Contractor to respond to and account for all such requests. 45 CFR 164.504(e)(2) (L) Contractor will provide, and will cause its Subcontractors and agents to provide, to System Agency periodic written certifications of compliance with controls and provisions relating to information privacy, security and breach notification, including without limitation information related to System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 3 of 11 System Agency Contract No.HHSREV100000793 data transfers and the handling and disposal of Confidential Information. 45 CFR 164.308, 164.530(c);.1 TAC 202 (M) Except as otherwise limited by this DUA, the Base Contract, or law applicable to the Confidential Information. Contractor may use or disclose PHI for the proper management and administration of Contractor or to cavy out Contractor's legal responsibilities if. 45 CFR 164.504(e)ri){l)(A) (1) Disclosure is Required by Law, provided that Contractor complies with Section 3.01(D); (2) Contractor obtains reasonable assurances from the Person to whom the information is disclosed that the Person will: (a) Maintain the confidentiality of the Confidential Information in accordance with this DUA; (b) Use or further disclose the information only as Required by Law or for the Authorized Purpose for which it was disclosed to the Person; and (c) Notify Contractor in accordance with Section 4.01 of any Event or Breach of Confidential Information of which the Person discovers or should have discovered with the exercise of reasonable diligence. 4S CFR 164.504(e)(4)(Y)(B) (I) Except as otherwise limited by this DUA, Contractor will, if requested by System Agency, use PHI to provide data aggregation services to System Agency, as that term is defined in the HIPAA, 45 C.F.R. § 164.501 and permitted by HIPAA. 45 CFR 164.504(e)(2)r)(B) (0) Contractor will, on the termination or expiration of this DUA or the Base Contract, at its expense, return to System Agency or Destroy, at System Agency's election, and to the extent reasonably feasible and permissible by law, all Confidential Information received from System Agency or created or maintained by Contractor or any of Contractor's agents or Subcontractors on System Agency's behalf if that data contains Confidential Information. Contractor will certify in writing to System Agency that all the Confidential Information that has been created, received, maintained, used by or disclosed to Contractor, has been Destroyed or returned to System Agency, and that Contractor and its agents and Subcontractors have retained no copies thereof. Notwithstanding the foregoing, Contractor acknowledges and agrees that it may not Destroy any Confidential Information if federal or state law, or System Agency record retention policy or a litigation hold notice prohibits such Destruction. If such return or Destruction is not reasonably feasible, or is impermissible by law, Contractor will immediately notify System Agency of the reasons such return or Destruction is not feasible, and agree to extend indefinitely the protections of this DUA to the Confidential Information and limit its further uses and disclosures to the purposes that make the return of the Confidential Information not feasible for as long as Contractor maintains such Confidential Information. 45 CFR 164.504(e)(2)ri)(J (P) Contractor will create, maintain, use, disclose, transmit or Destro Confidential Information in a secure fashion that protects against any reasonably anticipated threats or hazards to the security or integrity of such information or unauthorized uses. 45 CFR 164.306; 164.530(c) (Q) If Contractor accesses, transmits, stores, or maintains Confidential Information, Contractor will complete and return to System Agency at infosecurity(tDlihsc.state.tx.us the System Agency information security and privacy initial inquiry (SPI) at Attachment 2 . The SPI identifies basic privacy and security controls with which Contractor must comply to protect System Agency Confidential Information. Contractor will comply with periodic security controls compliance assessment and monitoring by System Agency as required by state and federal law, based on the type of Confidential Information Contractor creates, receives, maintains, uses, discloses or has access to and the Authorized Purpose and level of risk. Contractor's security controls will be based on the National Institute of Standards and Technology (NIST) Special Publication 800-53. Contractor will update its security controls assessment whenever there are significant changes in security controls for System Agency System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 4 of 11 System Agency Contract No.HHSREV 100000793 Confidential Information and will provide the updated document to System Agency. System Agency also reserves the right to request updates as needed to satisfy state and federal monitoring requirements. 45 CFR 164.306 (R) Contractor will establish, implement and maintain any and all appropriate procedural, administrative, physical and technical safeguards to preserve and maintain the confidentiality, integrity, and availability of the Confidential Information, and with respect to PHI, as described in the HIPAA Privacy and Security Regulations, or other applicable laws or regulations relating to Confidential Information, to prevent any unauthorized use or disclosure of Confidential Information as long as Contractor has such Confidential Information in its actual or constrictive possession. 45 CFR 164.308 (administrative safeguards); 164.310 (physical safeguards); 164.312 (technical safeguards); 164.530(c)(privacy safeguards) (S) Contractor will designate and identify, subject to System Agency approval, a Person or Persons, as Privacy Official 45 CFR 164.530(a)(1) and Information Security Official, each of whom is authorized to act on behalf of Contractor and is responsible for the development and implementation of the privacy and security requirements in this DUA. Contractor will provide name and current address, phone number and e-mail address for such designated officials to System Agency upon execution of this DUA and prior to any change. 45 CFR 164.308(a)(2) (T) Contractor represents and warrants that its Authorized Users each have a demonstrated need to know and have access to Confidential Information solely to the minimum extent necessary to accomplish the Authorized Purpose pursuant to this DUA and the Base Contract, and further, that each has agreed in writing to be bound by the disclosure and use limitations pertaining to the Confidential Information contained in this DUA. 45 CFR 164.502; 164.514(d) (U) Contractor and its Subcontractors will maintain an updated, complete, accurate and numbered list of Authorized Users, their signatures, titles and the date they agreed to be bound by the terms of this DUA, at all times and supply it to System Agency, as directed, upon request. (V) Contractor will implement, update as necessary, and document reasonable and appropriate policies and procedures for privacy, security and Breach of Confidential Information and an incident response plan for an Event or Breac to comply with the privacy, security and breach notice requirements of this DUA prior to conducting work under the DUA. 45 CFR 164.308; 164.316; 164.514(d); 164.530(1)(1) (W) Contractor will produce copies of its information security and privacy policies and procedures and records relating to the use or disclosure of Confidential Information received from, created by, or received, used or disclosed by Contractor on behalf of System Agency for System Agency's review and approval within 30 days of execution of this DUA and upon request by System Agency the following business day or other agreed upon time frame. 45 CFR 164.308, 164.514(d) (X) Contractor will make available to System Agency any information System Agency requires to fulfill System Agency's obligations to provide access to, or copies of, PHI in accordance with HIPAA and other applicable laws and regulations relating to Confidential Information. Contractor will provide such information in a time and manner reasonably agreed upon or as designated by the Secretary or other federal or state law. 45 CFR 164.504(e)(2)r)(1) (Y) Contractor will only conduct secure transmissions of Confidential Information whether in paper, oral or electronic form. A secure transmission of electronic Confidential Information in motion includes secure File Transfer Protocol (SFTP) or Encryption at an appropriate Ievel or otherwise protected as required by rule, regulation or law. System Agency Confidential Information at rest requires Encryption unless there is adequate administrative, technical, and physical security, or as otherwise System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 5 of l l System Agency Contract No.HHSREV 100000793 protected as required by rule, regulation or law. All electronic data transfer and communications of Confidential Information will be through secure systems. Proof of system, media or device security or Encryption must be produced to System Agency no later than 48 hours after System Agency's written request in response to a compliance investigation, audit or the Discovery of an Event or Breach. Otherwise, requested production of such proof will be made as agreed upon by the parties. De - identification of System Agency Confidential Information is a means of security. With respect to de - identification of PHI, "secure" means de -identified according to HIPAA Privacy standards and regulatory guidance. 45 CFR 164.312;164.530(d) W Contractor will comply with the following laws and standards if applicable to the t}pe of Confidential Information and Contractor's Authorized Purpose: • Title 1, Part 10. Chapter 202, Subchapter B. Texas Administrative Code; • The Privacy Act of 1974; • OMB Memorandum 07-16; • The Federal Information Security Management Act of 2002 (FISMA); • The Health Insurance Portability and Accountability Act of 1996H( IPAAI as defined in the DUA; • Internal Revenue Publication 1075 Tax Information Security Guidelines for Federal, State and Local Agencies; • National Institute of Standards and Technology (NIST) Special Publication 800-66 Revision 1 An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule; • NIST Special Publications 800-53 and 800-53A Recommended Security Controls for Federal Information Systems and Organizations, as currently revised; • NIST Special Publication 800-47 Security Guide for Interconnecting Information Technology Systems; • NIST Special Publication 800-88, Guidelines for Media Sanitization: • NIST Special Publication 800-111, Guide to Storage of Encryption Technologies for End User Devices containing PHI; and • Any other State or Federal law, regulation, or administrative rule relating to the specific System Agency program area that Contractor supports on behalf of System Agency. ARTICLE 4. BREACH NOTICE, REPORTING AND CORRECTION REQUIREMENTS Section 4.01. Breach or Event Notification to System Agency. 45 CFR 164.400-414 (A) Contractor will cooperate fully with System Agency in investigating, mitigating to the extent practicable and issuing notifications directed by System Agency, for any Event or Breach of Confidential Information to the extent and in the manner determined by System Agency. (B) Contractor'S obligation begins at the Discovery of an Event or Breach and continues as long as related activity continues, until all effects of the Event are mitigated to System Agency's satisfaction (the "incident response period"). 45 CFR 164.404 (C) Breach Notice: 1. Initial Notice. System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 6 of 11 System Agency Contract No.HHSREV 100000793 a. For federal information, including without limitation, Federal Tax Information, Social Security Administration Data. and Medicaid Client Information. within the first, consecutive clock hour of Discovery. and for all other types of Confidential Information not more than 24 hours after Discovery, or in a timeframe othenvise approved by System Agency in tvridirg, initially report to System Agency's Privacy and Security Officers via email at: privacvna.System AgencyC.state.tx.us and to the System Agency division responsible for this DUA: and IRS Publication 1075, Privacy Act of 1974, as amended by the Computer Matching and Privacy Protection Act of 1988, S U.S.0 § 552a, OMB Memorandum 07-16 as cited in System AgencyC-CMS Contracts for information exchange. b. Report all information reasonably available to Contractor about the Event or Breach of the privacy or security of Confidential Information. 45 CFR 164.410 c. Name, and provide contact information to System Agency for, Contractor's single point of contact who will communicate with System Agency both on and off business hours during the incident response period. 2. 48 -Hour Formal Notice. No later than 48 consecutive clock hours after Discovery, or a time within which Discovery reasonably should have been made by Contractor of an Event or Breach of Confidential Information provide formal notification to the State, including all reasonably available information about the Event or Breach, and Contractor's investigation, including without limitation and to the extent available: For (a) - (m) below: 45 CFR 164.400- 414 a. The date the Event or Breach occurred; b. The date of Contractor's and, if applicable, Subcontractor's Discoverv; c. A brief description of the Event or Breach: including how it occurred and who is responsible (or hypotheses, if not yet determined); d. A brief description of Contractor's investigation and the status of the investigation; e. A description of the types and amount of Confidential Information involved; f. Identification of and number of all Individuals reasonably believed to be affected, including first and last name of the individual and if applicable the, Legally authorized representative, last known address, age, telephone number, and email address if it is a preferred contact method, to the extent known or can be reasonably determined by Contractor at that time; g. Contractor's initial risk assessment of the Event or Breach demonstrating whether individual or other notices are required by applicable law or this DUA for System Agency approval, including an analysis of whether there is a low probability of compromise of the Confidential Information or whether any legal exceptions to notification apply; h. Contractor's recommendation for System Agency's approval as to the steps Individuals or Contractor on behalf of Individuals, should take to protect the Individuals from potential harm, including without limitation Contractor's provision of notifications, credit protection, claims monitoring, and any specific protections for a Legally Authorized Representative to take on behalf of an Individual with special capacity or circumstances; L The steps Contractor has taken to mitigate the harm or potential harm caused (including without limitation the provision of sufficient resources to mitigate); j. The steps Contractor has taken, or will take, to prevent or reduce the likelihood of recurrence of a similar Event or Breach; System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 7 of 11 System Agency Contract No.HHSPEV100000793 k. Identify, describe or estimate of the Persons, Workforce, Subcontractor, or Individuals and any law enforcement that may be involved in the Event or Breach; 1. A reasonable schedule for Contractor to provide regular updates to the foregoing in the future for response to the Event or Breach, but no less than every three (3) business days or as otherwise directed by System Agency, including information about risk estimations, reporting, notification, if any, mitigation, corrective action, root cause analysis and when such activities are expected to be completed; and m. Any reasonably available, pertinent information, documents or reports related to an Event or Breach that System Agency requests following Dish. Section 4.02 Investigation, Response and Mitigation. For A -F below. 45 CFR 164.308, 310 and 312; 164. 530 (A) Contractor will immediately conduct a full and complete investigation, respond to the Event or Breach, commit necessary and appropriate staff and resources to expeditiously respond, and report as required to and by System Agency for incident response purposes and for purposes of System Agency's compliance with report and notification requirements, to the satisfaction of System Agency. (B) Contractor will complete or participate in a risk assessment as directed by System Agency following an Event or Breach, and provide the final assessment, corrective actions and mitigations to System Agency for review and approval. (C) Contractor will fully cooperate with System Agency to respond to inquiries and proceedings by state and federal authorities, Persons and Individuals about the Event or Breach. (D) Contractor will fully cooperate with System Agency's efforts to seek appropriate injunctive relief or otherwise prevent or curtail such Event or Breach, or to recover or protect any Confidential Information, including complying with reasonable corrective action or measures, as specified by System Agency in a Corrective Action Plan if directed by System Agency under the Base Contract. Section 4.03 Breach Notification to Individuals and Reporting to Authoride& TGA Bus. & Comte. Code §521.053; 4S CFR 164.404 andividt►als),164.406 (Media);164.408 (Authorities) (A) System Agency may direct Contractor to provide Breach notification to Individuals, regulators or third -parties, as specified by System Agency following a Breach. (B) Contractor must obtain System Agency's prior written approval of the time, manner and content of any notification to Individuals, regulators or third -parties, or any notice required by other state or federal authorities. Notice letters will be in Contractor's name and on Contractor's letterhead, unless otherwise directed by System Agency, and will contain contact information, including the name and title of Contractor's representative, an email address and a toll-free telephone number, for the Individual to obtain additional information. (C) Contractor will provide System Agency with copies of distributed and approved communications. (D) Contractor will have the burden of demonstrating to the satisfaction of System Agency that any notification required by System Agency was timely made. If there are delays outside of Contractor's control, Contractor will provide written documentation of the reasons for the delay. System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 8 of 11 System Agency Contract No.HHSREV 100000793 (E) If System Agency delegates notice requirements to Contractor, System Agency shall, in the time and manner reasonably requested by Contractor, cooperate and assist with Contractors information requests in order to make such notifications and reports. ARTICLE 5. SCOPE OF WORK Scope of Work means the services and deliverables to be performed or provided by Contractor, or on behalf of Contractor by its Subcontractors or agents for System Agency that are described in detail in the Base Contract. The Scope of Work, including any future amendments thereto, is incorporated by reference in this DUA as if set out word-for-word herein. ARTICLE 6. GENERAL PROVISIONS Section 6.01 Orvnersliip of Coufndentiallnfornnation Contractor acknowledges and agrees that the Confidential Information is and will remain the property of System Agency. Contractor agrees it acquires no title or rights to the Confidential Information. Section 6.02 System Agency Connnnitonent and Obligations System Agency will not request that Contractor create, maintain, transmit, use or disclose PHI in any manner that would not be permissible under applicable law if done by System Agency. Section 6.03 System Agency Right to Inspection At any time upon reasonable notice to Contractor, or if System Agency determines that Contractor has violated this DUA, System Agency, directly or through its agent, will have the right to inspect the facilities, systems, books and records of Contractor to monitor compliance with this DUA. For purposes of this subsection, System Agency's agent(s) include, without limitation, the System Agency Office of the Inspector General or the Office of the Attorney General of Texas, outside consultants or legal counsel or other designee. Section 6.04 Term; Termination of DUA; Survival This DUA will take effect with the Base Contract, and will terminate upon termination of the Base Contract and as set forth herein. If the Base Contract is extended or amended, this DUA is updated automatically concurrent with such extension or amendment. (A) System Agency may immediately terminate this DUA and Base Contract upon a material violation of this DUA. (B) Termination or Expiration of this DUA will not relieve Contractor of its obligation to return or Destroy the Confidential Information as set forth in this DUA and to continue to safeguard the Confidential Information until such time as determined by System Agency. (D) If System Agency determines that Contractor has violated a material term of this DUA; System Agency may in its sole discretion: 1. Exercise any of its rights including but not limited to reports, access and inspection under this DUA or the Base Contract; or 2. Require Contractor to submit to a corrective action plan, including a plan for monitoring and plan for reporting, as System Agency may determine necessary to maintain compliance with this DUA; or System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 9 of 11 System Agency Contract No. HHSREV100000793 3. Provide Contractor with a reasonable period to cure the violation as determined by System Agency; or 4. Terminate the DUA and Base Contract immediately, and seek relief in a court of competent jurisdiction in Travis County, Texas. Before exercising any of these options, System Agency will provide written notice to Contractor describing the violation and the action it intends to take. (E) If neither termination nor cure is feasible, System Agency shall report the violation to the Secretary. (F) The duties of Contractor or its Subcontractor under this DUA survive the expiration or termination of this DUA until all the Confidential Information is Destroyed or returned to System Agency, as required by this DUA. Section 6.05 Governing Law, Venue and Litigation (A) The validity, construction and performance of this DUA and the legal relations among the Parties to this DUA will be governed by and construed in accordance with the laws of the State of Texas. (B) The Parties agree that the courts of Travis County, Texas, will be the exclusive venue for any litigation, special proceeding or other proceeding as between the parties that may be brought, or arise out of, or in connection with, or by reason of this DUA. Section 6.06 li&nctive Relief (A) Contractor acknowledges and agrees that System Agency may suffer irreparable injury if Contractor or its Subcontractor fails to comply with any of the terms of this DUA with respect to the Confidential Information or a provision of HIPAA or other laws or regulations applicable to Confidential Information. (B) Contractor further agrees that monetary damages may be inadequate to compensate System Agency for Contractor's or its Subcontractor's failure to comply. Accordingly, Contractor agrees that System Agency will, in addition to any other remedies available to it at law or in equity, be entitled to seek injunctive relief without posting a bond and without the necessity of demonstrating actual damages, to enforce the terns of this DUA. Section 6.07 Indemnification To the extent permitted by law, Contractor will indemnify, defend and hold harmless System Agency and its respective Executive Commissioner, employees, Subcontractors, agents (including other state agencies acting on behalf of System Agency) or other members of its Workforce (each of the foregoing hereinafter referred to as "Indemnified Party") against all actual and direct losses suffered by the Indemnified Party and all liability to third parties arising from or in connection with any breach of this DUA or from any acts or omissions related to this DUA by Contractor or its employees, directors, officers, Subcontractors or agents or other members of its Workforce. The duty to indemnify, defend and hold harmless is independent of the duty to insure and continues to apply even in the event insurance coverage required, if any, in the DUA or Base Contract is denied, or coverage rights are reserved by any insurance carrier. Upon demand, Contractor will reimburse System Agency for any and all losses, liabilities, lost profits, fuzes, penalties, costs or expenses (including reasonable attorneys' fees) which may for any reason be imposed upon any Indemnified Party by reason of any suit, claim, action, proceeding or demand by any third party to the extent caused by and which results from the Contractor's failure to meet any of its obligations under this DUA. To the extent permitted System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 10 of 11 System Agency Contract No.HHSREV100000793 by law, Contractor's obligation to defend, indemnify and hold harmless any Indemnified Party will survive the expiration or termination of this DUA. Section 6.08 Insntrance (A) Contractor represents and warrants that it maintains either self-insurance or commercial insurancewith policy limits sufficient to cover any liability arising from any acts or omissions by Contractor or its employees, directors, officers, Subcontractors, or agents or other members of its Workforce under this DUA. Contractor warrants that System Agency will be a loss payee and beneficiary for any such claims. . (B) Contractor will provide System Agency with written proof that required insurance coverage is in effect, at the request of System Agency. Section 6.09 Fees and Costs Except as otherwise specified in this DUA or the Base Contract, including but not limited to requirements to insure or indemnify System Agency, if any legal action or other proceeding is brought for the enforcement of this DUA, or because of an alleged dispute, contract violation, Event. Breach, default, misrepresentation, or injunctive action, in connection with any of the provisions of this DUA, each party will bear their own Iegal expenses and the other cost incurred in that action or proceeding. Section 6.10 Entiretyof the Contract This Data Use Agreement is incorporated by reference into the Base Contract and, together with the Base Contract, constitutes the entire agreement between the parties. No changc, waiver, or discharge of obligations arising under those documents will be valid unless in writing and executed by the party against whom such change, waiver, or discharge is sought to be enforced. Section 6.11 Automatic Amendment and Interpretation Upon the effective date of any amendment or issuance of additional regulations to 1U , or any other law applicable to Confidential Information, this DUA will automatically be amended so that the obligations imposed on System Agency or Contractor remain in compliance with such requirements. Any ambiguity in this DUA will be resolved in favor of a meaning that permits System Agency and Contractor to comply with HIPAA or any other law applicable to Confidential Information. System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Page 1 l of 11 System Agency Contract No.HHSREV 100000793 ATTACHMENT I. SUBCONTRACTOR AGREEMENT FORM System Agency CONTRACT NUMBER RHSREV100000793 The DUA between System Agency and Contractor establishes the permitted and required uses and disclosures of Confidential Information by Contractor. Contractor has subcontracted with (SUBContractor) for performance of duties on behalf of CONTACTOR which are subject to the DUA. SUBContractor acknowledges, understands and agrees to be bound by the identical terms and conditions applicable to Contractor under the DUA, incorporated by reference in this Agreement, with respect to System Agency Confidential Information. Contractor and SUBContractor agree that System Agency is a third -party beneficiary to applicable provisions of the subcontract. System Agency has the right but not the obligation to review or approve the terms and conditions of the subcontract by virtue of this Subcontractor Agreement Form. Contractor and SUBContractor assure System Agency that any Breach or Event as defined by the DUA that SUBContractor Discovers will be reported to System Agency by Contractor in the time, manner and content required by the DUA. If Contractor knows or should have known in the exercise of reasonable diligence of a pattern of activity or practice by SUBContractor that constitutes a material breach or violation of the DUA or the SUBContractor's obligations Contractor will: 1. Take reasonable steps to cure the violation or end the violation, as applicable; 2. If the steps are unsuccessful, terminate the contract or arrangement with SUBContractor, if feasible; 3. Notify System Agency immediately upon reasonably discovery of the pattern of activity or practice of SUBContractor that constitutes a material breach or violation of the DUA and keep System Agency reasonably and regularly informed about steps Contractor is taking to cure or end the violation or terminate SUBCONTACTOWs contract or arrangement. This Subcontractor Agreement Form is executed by the parties in their capacities Indicated below. CONTRACTOR BY: NAME: SUBCONTRACTOR BY: NAME: TITLE: TITLE: DATE 9201 . DATE: System Agency Data Use Agreement V.8.3 HIPAA Omnibus Compliant April 1, 2015 Attachment 1 Page 1 of 1