Business Associate Agreement

THIS BUSINESS ASSOCIATE AGREEMENT (the “BAA”) is made and entered into between Quadient CXM USA, Inc., a Massachusetts corporation (“Quadient” or “Business Associate”), and the Customer as defined in the Main Agreement (“Customer” or “Covered Entity”).

I. WHEREAS, Customer is a Covered Entity, or is a Business Associate to one or more Covered Entities, that possesses information about individuals that is protected under the Health Insurance Portability and Accountability Act of 1996, the Health Information Technology for Economic and Clinical Health Act (commonly referred to as the “HITECH Act”), and the regulations promulgated under the foregoing from time to time by the United States Department of Health and Human Services (“HHS”) (collectively, as amended from time to time, “HIPAA”); and

II. WHEREAS, Customer and Quadient have entered into one or more agreements (collectively, the “Agreement”) pursuant to which Quadient and its affiliates will provide certain specified services to Customer (the “Services”). In the course of providing the Services, Customer may make available to Quadient or have Quadient obtain or create on its behalf information that may be deemed protected health information subject to the provisions of HIPAA and by providing the Services pursuant to the Main Agreement, Quadient will become a “business associate” of the Customer as such term is defined under HIPAA; and

III. WHEREAS, the Parties are committed to complying with all federal and state laws governing the confidentiality and privacy of health information, including, but not limited to, the Standards for Privacy of Individually Identifiable Health Information found at 45 CFR Part 160 and Part 164, Subparts A and E (collectively, the “Privacy Rule”) and the Federal Confidentiality of Alcohol and Drug Abuse Patient Records Law and implementing regulations as set forth at 42 CFR Part 2 (“Part 2”); and

IV. WHEREAS, the Parties intend to protect the privacy and provide for the security of Protected Health Information disclosed to Business Associate pursuant to the terms of this Agreement, HIPAA and other applicable laws. NOW THEREFORE, in consideration of the mutual covenants and conditions contained herein, the Parties agree as follows:

1. Definitions.

1.1. "Catch-all definition": Capitalized terms used but not otherwise defined in this BAA shall have the meanings ascribed in HIPAA including, but not limited to Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.

1.2. "Effective Date” means the later of (i) the date on which the Main Agreement becomes effective and (ii) the first date upon which Quadient creates or receives PHI as a Business Associate of Customer.“PHI” means Protected Health Information received by Quadient from or on behalf of Customer or created by Quadient for or on behalf of Customer.

2. Permitted Uses.

Quadient may use PHI only as permitted or required by this BAA for the following purposes:

(i) as necessary to provide the Services;

(ii) to carry out its legal responsibilities;

(iii) for the proper business management and administration of Quadient;

(iv) as Required By Law.

3. Permitted Disclosures.

Quadient may disclose PHI only as permitted or required by this BAA, in compliance with applicable laws and regulations, for the following purposes:

(i) as necessary to provide the Services;

(ii) for the proper business management and administration of Quadient or to carry out its legal responsibilities, if Quadient has obtained reasonable assurances that the recipient will (a) hold such PHI in confidence, (b) use or further disclose it only for the purpose for which it was received or as Required By Law, and (c) notify Quadient of any instance of which the recipient becomes aware in which the confidentiality of such PHI has been breached;

(iii) as otherwise Required By Law; provided, however, that any disclosure to a Subcontractor of Quadient shall be pursuant to a written agreement between Quadient and such Subcontractor containing substantially the same restrictions and conditions on the use and disclosure of PHI as are set forth in this BAA. For purposes of clarity, Quadient affiliates shall not be deemed Subcontractors hereunder.

4. Prohibited Uses and Disclosures.

Subject to Customer’s compliance with its obligations set forth in Section 14 as applicable, Quadient shall not use or further disclose PHI in a manner that would violate HIPAA if done by the Customer. Quadient shall not sell PHI.

5. Safeguards.

Quadient shall establish and maintain appropriate safeguards intended to prevent use or disclosure of PHI other than as provided in this BAA. Without limiting the foregoing, Quadient shall establish and maintain, in compliance with HIPAA and any applicable guidance issued pursuant thereto, administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of any PHI that is Electronic Protected Health Information or any other Electronic Protected Health Information maintained or transmitted by Quadient for or on behalf of Customer, and Quadient shall establish and maintain policies and procedures, and comply with the documentation requirements, set forth in HIPAA.

6. Reports to Customer; Breach Notification.

6.1. Without unreasonable delay and in no case later than ten (10) days after discovering a Breach involving PHI that is Unsecured Protected Health Information, Quadient shall report such Breach to Customer in writing, setting forth the date of discovery thereof, the identities of affected individuals (or, if such identities are unknown at that time, the classes of such individuals), a general description of the nature of the incident, and such other information as is required pursuant to HIPAA or reasonably requested by Customer. For purposes hereof, a Breach shall be deemed discovered by Quadient when it is known to Quadient or, by exercising reasonable diligence, would have been known to Quadient.

6.2. Quadient shall report to Customer in writing any use or disclosure of PHI that is not permitted by this BAA, other than a Breach involving PHI that is Unsecured Protected Health Information, within ten (10) business days of Quadient’s discovery thereof.

6.3. Quadient shall report to Customer in writing any Security Incident involving PHI that is Electronic Protected Health Information within ten (10) business days of Quadient’s discovery thereof. The parties acknowledge and agree that this section constitutes notice by Quadient to Customer of the ongoing occurrence of incidents that may constitute Security Incidents but that are trivial and do not result in unauthorized access, use, or disclosure of PHI that is Electronic Protected Health Information, including without limitation pings and other broadcast attacks on Quadient’s firewall, port scans, unsuccessful log-on attempts, and denials of service, for which no additional notice to Customer shall be required.

7. Mitigation.

Quadient shall take all actions reasonably necessary and cooperate with Customer as reasonably requested to mitigate, to the extent practicable, any harmful effect of such occurrence.

8. Minimum Necessary.

Quadient shall request, use, and disclose only the minimum amount of PHI necessary to provide the Services.

9. Access and Amendment.

Quadient maintains that as a part of its Services that it does not maintain any PHI that is a part of a Designated Record Set.

Quadient shall notify Customer promptly upon receipt of a request from such an Individual for access to or a copy of such Individual’s PHI or to amend such Individual’s PHI that may be contained in a Designated Record Set. To the extent permitted under HIPAA, and except as otherwise required upon the order of a court of competent jurisdiction, (i) Quadient shall direct such Individual to make such request of Customer and (ii) Quadient shall not consent to such access, deliver such copy, or comply with such request except as directed by Customer.

10. Accounting for Disclosures.

Quadient shall document all disclosures of PHI by Quadient and information related to such disclosures as would be required for Customer to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with HIPAA. Quadient shall maintain such information for the applicable period set forth in HIPAA. Quadient shall deliver such information to Customer or, upon Customer’s request, to the Individual, in the time and manner reasonably designated by Customer, in order for Customer to respond to a request by an Individual for an accounting of disclosures of PHI in accordance with HIPAA. The obligations set forth in this section shall survive the expiration or any termination of this BAA and shall continue, as to a given instance of a disclosure, until the earlier of (i) the passing of the time required for such information to be maintained pursuant to HIPAA or (ii) the delivery to Customer of all such information in a form and medium reasonably satisfactory to Customer and the return or destruction of all PHI as provided in this BAA.

11. Additional Restrictions.

If Customer notifies Quadient that Customer has agreed to be bound by additional restrictions on the uses or disclosures of PHI pursuant to HIPAA, Quadient shall be bound by such additional restrictions and shall not use or disclose PHI in violation of such additional restrictions.

12. Covered Entity Obligations.

To the extent Quadient is to carry out a Covered Entity's obligation under the Privacy Rule, Quadient will comply with the requirements of the Privacy Rule that apply to the Covered Entity in the performance of such obligation.

13. Audit.

If Quadient receives a request, made on behalf of the Secretary of the Department of Health and Human Services, that Quadient make its internal practices, books, and records relating to the use or disclosure of PHI available to the Secretary of the Department of Health and Human Services for the purposes of determining Customer’s or Quadient’s compliance with HIPAA, Quadient promptly shall notify Customer of such request and, unless enjoined from doing so by order of a court of competent jurisdiction in response to a challenge raised by Customer or Quadient (which challenge Quadient shall not be obligated to raise), Quadient shall comply with such request to the extent required of it by applicable law. Nothing in this BAA shall waive any attorney-client privilege or other privilege applicable to either party.

14. Remuneration.

Quadient shall not receive remuneration, directly or indirectly, in exchange for PHI; provided, however, that this prohibition shall not affect payment to Quadient by Customer pursuant to the Services.

15. Obligations of Customer.

Customer shall (i) notify Quadient of any limitation in Customer’s Notice of Privacy Practices to the extent that such limitation may affect Quadient's use or disclosure of PHI, (ii) notify Quadient of any changes in, or revocation of, permission by an Individual to use or disclose PHI, to the extent that such change may affect Quadient’s use or disclosure of PHI, (iii) notify Quadient of any restriction on the use or disclosure of PHI to which Customer has agreed in accordance with HIPAA, to the extent that such restriction may affect Quadient's use or disclosure of PHI, and (iv) obtain any authorization or consents as may be Required by Law for any of the uses or disclosures of PHI pursuant to the Services including but not limited to Part 2. To the extent that Customer notifies Quadient of a change as specified in this section, to the extent that the Services to which the notice relates can still be performed, Customer shall be responsible for any additional costs resulting from the additional restrictions communicated in the notice. In the event that a notice provided under this section renders the Services to be provided impossible or impracticable, Quadient may terminate the relevant Agreement with immediate effect and without any further liability to the Customer upon written notice to the Customer.

16. De-identified Data.

Customer acknowledges that in order for Quadient to provide certain activity reporting to Customer as part of the Services, Quadient will de-identify such PHI. All such de-identification shall be accomplished in accordance with the applicable provisions of HIPAA, and Quadient during and after the term of this BAA may use and disclose such de-identified information and other information created or received in the course of the Services for any lawful purpose provided that any disclosure thereof shall not identify Customer.

17. Term and Termination.

This BAA shall become effective on the Effective Date and shall continue in effect until the earlier to occur of (i) expiration or termination of the Agreement or (ii) termination pursuant to this section. Either party may terminate this BAA effective immediately if it determines that the other party has breached a material provision of this BAA and failed to cure such breach within thirty (30) days of being notified by the other party of the breach. If the non-breaching party reasonably determines that cure is not possible, such party may terminate this BAA effective immediately upon written notice to other party.

18. Effect of Termination.

Upon termination of this BAA, Quadient shall (i) if feasible, return to Customer or destroy all PHI that Quadient maintains in any form and retain no copies of such PHI, or (ii) if return or destruction is not feasible, notify Customer and extend the protections of this BAA to the PHI and limit its further use or disclosure to those purposes that make the return or destruction of the PHI infeasible. The requirements of this section shall survive termination or expiration of this BAA and shall be in force as long as any PHI remains in the custody or control of Quadient.

19. Part 2.

To the extent that in performing its Services for or on behalf of Customer, Quadient uses, discloses, maintains, or transmits PHI that is protected by Part 2, Quadient acknowledges and agrees that in receiving, storing, processing or otherwise dealing with any such patient records, it is fully bound by the Part 2 regulations; and, if necessary, will resist in judicial proceedings any efforts to obtain access to patient records except as permitted by the Part 2 regulations at the sole cost and expense of Customer. Notwithstanding any other language in the Agreement or this BAA, Customer acknowledges and agrees that any patient information that is protected by Part 2 is subject to protections that prohibit Quadient from disclosing such information to agents or subcontractors without the specific written consent of the subject individual.

20. Miscellaneous.

20.1. Amendments. This BAA may not be modified, nor shall any provision hereof be waived or amended, except in a writing duly signed by authorized representatives of the parties in accordance with the Main Agreement; provided, however, that upon the enactment of any law or regulation affecting the use or disclosure of PHI, or on the publication of any decision of a court of competent jurisdiction relating to any such law, or the publication of any interpretive policy or opinion of any governmental agency charged with the enforcement of any such law or regulation, Quadient may, by written notice, propose to amend this BAA in such a manner as Quadient reasonably determines necessary to comply therewith, and such proposed amendment shall become operative unless Customer rejects such amendment by written notice to Quadient within thirty (30) days thereafter, in which case, either party may terminate this BAA by written notice to the other.

20.2. Notices. Notices and reports given under this BAA shall be in writing and sent via United States Postal Service Certified Mail to the addresses provided below or otherwise designated by the parties in accordance with the Main Agreement:

If to Quadient:

  • Attn: Counsel for the Americas

  • Quadient CXM USA, Inc.

  • 478 Wheelers Farms Road

  • Milford, CT 06461

20.3. Governing Law. This BAA shall be governed and construed under the laws of the state of Connecticut, other than its conflicts of laws principles.

20.4. Waiver. A waiver with respect to one event shall not be construed as continuing, or as a bar to or waiver of, any right or remedy as to subsequent events.

20.5. No Third Party Beneficiaries. Nothing express or implied in this BAA is intended to confer, nor shall anything herein confer, upon any person other than the parties and the respective successors or assigns of the parties, any rights, remedies, obligations, or liabilities whatsoever.

20.6. Interpretation. In the event of an inconsistency between the provisions of this BAA and mandatory provisions of HIPAA, as amended, or its interpretation by any court or regulatory agency with authority over either party hereto, HIPAA (interpreted by such court or agency, if applicable) shall control. Where provisions of this BAA are different from those mandated under HIPAA, but are nonetheless permitted by such rules as interpreted by relevant courts or agencies, the provisions of this BAA shall control.

20.7. Counterparts. This BAA may be executed in counterparts, each of which shall be deemed an original and all of which shall constitute one and the same instrument. Such counterparts may be delivered in faxed or scanned electronic form, and each shall be deemed an original.

IN WITNESS WHEREOF, Quadient and Customer acknowledge and agree that this BAA forms part of and is incorporated into the Main Agreement and shall be effective as of the Effective Date.