Compliance & Legal
HIPAA Statement &
Business Associate Agreement
At Prime Speech Solutions, we are committed to maintaining the highest standards of data privacy and security for our clients' Protected Health Information.
HIPAA Statement
Prime Speech Solutions has hired an independent third party auditor that is compliant with the rules and regulations of HIPAA. For more details, please contact privacy@primespeechsolutions.com.
Business Associate Agreement for Prime Speech Solutions “Covered Entity” Customers
These Standard HIPAA Business Associate Agreement Terms and Conditions (“HIPAA Addendum”) shall be incorporated into the Master Service Agreement for Customers that are Covered Entities (as defined below) that provide Protected Health Information (“PHI”) (as defined below) to Prime Speech Solutions in connection with the Prime Speech Solutions for Local Business and Enterprise services they have purchased.
These terms supplement the purchase agreement between Prime Speech Solutions and Customers (“Underlying Agreement”) in order to comply with the federal Standards for HIPAA of Individually Identifiable Health Information, located at 45 C.F.R. Part 160 and Part 164, Subparts A through E (“HIPAA Rule”) and the Health Information Technology for Economic and Clinical Health Act, Public Law 111-005 (the “HITECH Act”).
1. Catch-all Definitions
The following terms used in this Agreement shall have the same meaning as those terms in the HIPAA Rules: Breach, Data Aggregation, Designated Record Set, Disclosure, Health Care Operations, Individual, Minimum Necessary, Notice of Privacy Practices, Protected Health Information, Required By Law, Secretary, Security Incident, Subcontractor, Unsecured Protected Health Information, and Use.
2. Specific Definitions
Terms used, but not otherwise defined, in this HIPAA Addendum shall have the same meaning as those terms in the Privacy Rule or the HITECH Act:
- “Breach” shall have the same meaning given to such term under 42 U.S.O § 17921.
- “Business Associate” shall generally have the same meaning as the term “business associate” at 45 CFR 160.103, and in reference to the party to this agreement, shall mean Prime Speech Solutions.
- “Covered Entity” shall generally have the same meaning as the term “covered entity” at 45 CFR 160.103.
- “HIPAA Rules” shall mean the Privacy, Security, Breach Notification, and Enforcement Rules at 45 CFR Part 160 and Part 164.
3. Obligations and Activities of Business Associate
Prime Speech Solutions agrees to:
1- Use and Disclosure of PHI
Prime Speech Solutions shall not use or disclose PHI other than as permitted or required by this HIPAA Addendum or as Required by Law. Prime Speech Solutions shall not use or disclose PHI for fundraising or marketing purposes.
2- Safeguards
Prime Speech Solutions shall use appropriate safeguards and comply with Subpart C of 45 CFR Part 164 with respect to electronic PHI to prevent any unauthorized use or disclosure.
3- Mitigation
Prime Speech Solutions shall mitigate, to the extent practicable, any harmful effect that is known to Prime Speech Solutions of a use or disclosure of PHI in violation of this Addendum.
4- Reporting
Prime Speech Solutions shall report to Covered Entity any use or disclosure not provided for, including breaches of unsecured PHI and any security incidents. Prime Speech Solutions will notify Covered Entity of the breach within thirty (30) business days.
4. Permitted Uses and Disclosures by Prime Speech Solutions
- 1- Permitted Uses and Disclosures: Except as otherwise limited in this HIPAA Addendum, Prime Speech Solutions may use or disclose PHI to perform functions, activities, or services for or on behalf of the Covered Entity as specified in the Underlying Agreement.
- 2- Management and Administration: Prime Speech Solutions may use PHI for the proper management and administration of Prime Speech Solutions or to carry out its legal responsibilities.
- 3- Minimum Necessary: Prime Speech Solutions shall request, use, and disclose only the minimum amount of PHI necessary to accomplish the purpose of the use, disclosure, or request.
5. Term and Termination
Term: The Term of this HIPAA Addendum shall be effective as of the first day that the Covered Entity provides PHI to Prime Speech Solutions and shall terminate when all PHI is destroyed or returned to the Covered Entity.
Termination for Cause: Prime Speech Solutions authorizes termination of this Agreement by the Covered Entity, if the Covered Entity determines Prime Speech Solutions has violated a material term of the Agreement, following a 60-day advance written notice.
Compliance Support
For further details regarding our HIPAA compliance protocols or specific BAA terms, please contact our privacy office.
Contact Privacy Office