IMPORTANT – PLEASE READ CAREFULLY
This Business Associate Agreement (“Agreement”) is entered into between the customer or service provider (“Covered Entity”) and CyberSentriq (“Business Associate”), effective as of the date of signature and/or documented agreement (“Effective Date”).
1.1 The Covered Entity is a “covered entity” or “business associate” as defined under the Health Insurance Portability and Accountability Act of 1996, as amended, including the HITECH Act and associated regulations (“HIPAA”).
1.2 The parties have entered into, or will enter into, one or more agreements (“Underlying Agreement(s)”) under which CyberSentriq provides services.
1.3 In providing such services, CyberSentriq may create, receive, maintain, or transmit Protected Health Information (“PHI”).
1.4 Accordingly, CyberSentriq acts as a “Business Associate” to the Covered Entity under HIPAA.
For the purposes of this Agreement:
3.2. CyberSentriq shall not use or disclose PHI in any manner that would violate HIPAA if done by the Covered Entity.
4.1. CyberSentriq shall implement appropriate administrative, technical, and organizational safeguards to:
4.2 CyberSentriq shall comply with applicable requirements of the HIPAA Security Rule for electronic PHI.
4.3 CyberSentriq maintains security controls aligned to industry best practices, including:
5.1. CyberSentriq shall report to the Covered Entity:
5.2. Such notification shall be made without unreasonable delay and in accordance with applicable legal requirements.
6.1. CyberSentriq may engage subcontractors who may have access to PHI.
6.2. CyberSentriq shall ensure that any such subcontractor:
6.3. CyberSentriq remains responsible for subcontractor compliance.
7.1. CyberSentriq shall, where applicable:
to enable the Covered Entity to meet its obligations under HIPAA.
CyberSentriq shall make available its internal practices, records, and policies relating to PHI to:
for purposes of demonstrating compliance with HIPAA.
9.1. This Agreement shall terminate upon termination of the Underlying Agreement unless otherwise required by law.
9.2. Upon termination, CyberSentriq shall:
9.3. If return or destruction is not feasible, CyberSentriq shall continue to protect such PHI.
The Covered Entity agrees to:
Each party shall be responsible for its own compliance with HIPAA.
Failure to comply may result in:
CyberSentriq acts as an independent contractor and not as an agent of the Covered Entity.
CyberSentriq operates in the United Kingdom, South Africa, Ireland, the United States of America, and other jurisdictions from time to time.
This Agreement shall be governed by the laws of the jurisdictions listed above, unless otherwise required by applicable HIPAA jurisdictional requirements.