Healthcare Addendum & Business Associate Agreement
Sector-specific terms for hospitals, clinics, and healthcare systems. Attaches to and modifies the MSA where the deploying Authority is a HIPAA Covered Entity or where Personal Data may include Protected Health Information.
1. Applicability
Where the Authority is a "Covered Entity" under the Health Insurance Portability and Accountability Act ("HIPAA," 45 C.F.R. Parts 160, 162, 164) or a "Business Associate" that engages WCE to perform functions on its behalf, this Addendum constitutes the required Business Associate Agreement ("BAA"). Terms not defined here have the meaning given in HIPAA.
2. Permitted uses and disclosures of PHI
WCE, as Business Associate, shall use or disclose Protected Health Information ("PHI") only as necessary to perform the Purpose under the MSA, as required by law, or for the proper management and administration of WCE consistent with 45 C.F.R. § 164.504(e)(4). WCE shall not use or disclose PHI in a manner that would violate HIPAA if done by the Covered Entity.
3. Minimum necessary
WCE shall request, use, and disclose only the minimum PHI necessary to accomplish the Purpose. Notifications generated by the Platform are categorical and are designed not to be PHI; where PHI may nonetheless be present (for example, in metadata associated with a hospital operator's session), the minimum-necessary rule applies.
4. Safeguards
WCE shall implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of PHI, consistent with 45 C.F.R. Part 164, Subpart C.
5. Reporting of breaches and security incidents
WCE shall report to the Covered Entity, without unreasonable delay and in no case later than seventy-two (72) hours after discovery, any Breach of Unsecured PHI, and shall report any Security Incident of which WCE becomes aware. Reports shall include the information required by 45 C.F.R. §§ 164.404(c) and 164.410(c).
6. Subcontractors
WCE shall enter into a written agreement with each subcontractor that creates, receives, maintains, or transmits PHI on behalf of WCE, imposing on the subcontractor the same restrictions and conditions that apply to WCE under this Addendum.
7. Access, amendment, and accounting
WCE shall, at the Covered Entity's request and in the time and manner reasonably designated by the Covered Entity, provide access to PHI, incorporate amendments to PHI, and make available information required to provide an accounting of disclosures.
8. Interaction with hospital security
Where the Platform is integrated with hospital security operations (e.g., emergency-department entry vestibules), operator response to a Notification shall be coordinated with clinical operations to avoid interference with patient care. WCE will not access clinical systems and shall not receive clinical data unless expressly required for the Purpose, which is not anticipated.
9. Return or destruction of PHI
Upon termination or expiration of the MSA, WCE shall, if feasible, return or destroy all PHI, retaining no copies. Where return or destruction is not feasible, WCE shall extend the protections of this Addendum to the PHI and limit further uses and disclosures for so long as the PHI is maintained.
10. Access by the Secretary
WCE shall make its internal practices, books, and records relating to the use and disclosure of PHI available to the Secretary of the U.S. Department of Health and Human Services for purposes of determining the Covered Entity's compliance with HIPAA, on reasonable notice.
11. State law
Where state law imposes additional requirements more protective than HIPAA (California CMIA, New York SHIELD Act, Texas HB 300, or analogous), those requirements apply concurrently.
12. Order of precedence
In the event of a conflict with the body of the MSA, this Addendum governs to the extent required by HIPAA or applicable state medical-privacy law.
This Addendum attaches to the MSA and is effective concurrently with it.