1. Definitions
-
Terms used but not otherwise defined in this Agreement shall have the same meaning as
those terms defined in HIPAA, including, but not limited to, "Business Associate," "Covered
Entity," "Protected Health Information" ("PHI"), "Electronic Protected Health Information"
("ePHI"), and "Breach."
Business Associate
A "Business Associate" is any person or entity that performs functions or activities on behalf of, or
provides services to, a Covered Entity that involve the use or disclosure of Protected Health
Information (PHI). Examples include third-party billing companies, cloud storage providers, or IT
service providers who handle PHI.
Covered Entity
A "Covered Entity" refers to health plans, healthcare clearinghouses, and healthcare providers who
transmit any health information in electronic form in connection with transactions covered by
HIPAA. These entities are directly responsible for protecting the privacy and security of patient
information.
Protected Health Information (PHI)
"PHI" is any information, whether oral or recorded in any form, that is created or received by a
healthcare provider, health plan, employer, or healthcare clearinghouse, and relates to the past,
present, or future physical or mental health condition of an individual, the provision of healthcare,
or payment for healthcare. PHI can include names, addresses, birthdates, Social Security numbers,
and medical records.
Electronic Protected Health Information (ePHI)
"ePHI" is any PHI that is created, stored, transmitted, or received electronically. This includes
digital records, emails containing patient data, and electronic billing information. ePHI is subject to
additional security requirements under the HIPAA Security Rule.
Breach
A "Breach" refers to the impermissible use or disclosure of PHI that compromises its security or
privacy, unless the Covered Entity or Business Associate can demonstrate a low probability that the
PHI has been compromised based on a risk assessment. Examples include data theft or loss of
unencrypted devices containing PHI.
[Explanation: This clause ensures the contract uses the same terminology as HIPAA regulations,
providing clarity and legal consistency.]