|(A)
|
Act: The Health Insurance Portability and Accountability Act of 1996.
|(B)
|
Benefit Plans Committee: The Dynegy Inc. Benefit Plans Committee.
|(C)
|
Business Associate: Individual or entity, other than an employee of the Employer or Dynegy Inc., that provides services to the Plan, such as a third party administrator, COBRA vendor or utilization review organization.
|(D)
|
Contact Person: The person appointed to serve as contact person pursuant to Section 14.8 and Article III of the Manual for purposes of complaints.
|(E)
|
Employer: The Company, each Participating Employer and Dynegy Inc.
|(F)
|
Health Component: Any of the health components of the Plan designated as such by the Dynegy Inc. Benefit Plans Committee consisting of the DNE Group Medical Plan, the DNE Employee Assistance Plan; the DNE Dental Plan; the DNE Vision Plan and the medical benefits program of DNE Medical and Group Term Life Insurance Plan for Retirees and Surviving Spouses; and any health maintenance organization offered as a benefit alternative under the Plan.
|(G)
|
Manual: The Dynegy Northeast Generation, Inc. Comprehensive Welfare Benefits Plan Protected Health Information Policies and Procedures.
-2-
|(H)
|
Non-Health Components: Components of the Plan other than the Health Components.
|(I)
|
PHI: Individually identifiable health information which is protected pursuant to the Act and the Regulations.
|(J)
|
Privacy Officer: The individual or entity appointed to serve as the Plan’s Privacy Officer pursuant to Section 14.7 and Article III of the Manual.
|(K)
|
Regulations: The regulations promulgated pursuant to the Act at 45 C.F.R. Parts 160 and 164, Subpart E and, effective as of April 20, 2005, Subpart C.
|(L)
|
Security Officer: Effective as of April 20, 2005, the individual or entity appointed to serve as the Plan’s Security Officer pursuant to Section 14.10.
|(M)
|
SHI: Information that summarizes the claims history, claims expense or type of claims experienced by covered persons under the Plan as such term is described in Section 164.504 of the Regulations.
|(A)
|
For the purpose of enabling the Employer to obtain premium bids from health insurers for providing health insurance coverage under the Health Component;
|(B)
|
For purposes of determining whether and, if so, how to modify or amend the Health Component; or
|(C)
|
For purposes of determining whether and, if so, how to terminate the Health Component, in whole or in part.
-3-
|(A)
|
The Employer will not use or further disclose the information other than as permitted or required by the Plan documents or as required by law or the Regulations as set forth in the Manual;
|(B)
|
The Employer will ensure that any agents, including a subcontractor, to whom it provides PHI received from a Health Component agree to the same restriction and conditions that apply to the Employer with respect to such information;
|(C)
|
The Employer will not use or disclose the information for employment-related actions and decisions or in connection with any other benefit or employee benefit plan of the Employer;
|(D)
|
The Employer will report to the Plan any use or disclosure of the information that is inconsistent with the uses or disclosures provided for of which it becomes aware;
|(E)
|
The Employer will make PHI available to Participants in accordance with Section 164.524 of the Regulations as set forth in the Manual;
|(F)
|
The Employer will provide Participants with the right to amend their PHI and will incorporate any amendments to PHI in accordance with Section 164.526 of the Regulations as set forth in the Manual;
|(G)
|
The Employer will provide to Participants an accounting of disclosures of their PHI for reasons other than treatment, payment or health care operations or pursuant to an authorization in accordance with Section 164.528 of the Regulations as set forth in the Manual;
-4-
|(H)
|
The Employer will make its internal practices, books and records relating to the use and disclosure of PHI received from a Health Component available to the Secretary of Health and Human Services for purposes of determining compliance by the Health Component with the Regulations;
|(I)
|
If feasible, the Employer will return or destroy all PHI received from a Health Component that the Employer still maintains in any form and retain no copies of such information when no longer needed for the purpose for which disclosure was made or if such return or destruction is not feasible, the Employer will limit further uses and disclosures to those purposes that make the return or destruction of the information infeasible;
|(J)
|
The Employer will ensure the adequate separation required pursuant to Section 14.6 below;
|(K)
|
Effective as of April 20, 2005, the Employer will implement administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the electronic PHI that it creates, receives, maintains or transmits on behalf of the Plan (except with respect to enrollment and disenrollment information, SHI and PHI disclosed pursuant to an authorization under Section 164.508 of the Regulations) and shall ensure that any agents (including subcontractors) to whom it provides such electronic PHI agree to implement reasonable and appropriate security measures to protect such information; and
|(L)
|
Effective as of April 20, 2005, the Employer will report to the Plan any security incident of which it becomes aware.
|(A)
|
The only employees, classes of employees or other persons under the control of the Employer to be given access to PHI disclosed to the Employer or who receive PHI relating to treatment, payment under, health care operations of, or other matters pertaining to a Health Component in the ordinary course of business are those identified in new Appendix C to the Plan, a copy of which is attached hereto. Appendix C to the Plan may be revised and updated at the direction of the Privacy Officer. Effective as of April 20, 2005, the Employer will ensure that the provisions of this Section 14.5 are supported by reasonable and appropriate security measures to the extent that the designees have access to electronic PHI.
-5-
|(B)
|
The access to and use by the Employer and the other individuals and entities described in item (A) above is restricted to (i) the Plan sponsor functions with respect to which the Firm is entitled to receive SHI pursuant to Section 14.4 above, (ii) uses and disclosures described in an authorization by a Plan Participant, (iii) uses and disclosures that are described to Plan Participants in the Plan’s notice of privacy practices and (iv) the Health Component administration functions that the Employer performs in connection with the operation and administration of the Health Component consisting of:
|(1)
|
conducting quality assessment and improvement activities (provided that the obtaining of generalizable knowledge is not the primary purpose of any studies resulting from such activities) and related functions that do not include medical treatment;
|(2)
|
evaluating health plan performance;
|(3)
|
underwriting, premium rating, and other activities relating to the creation, renewal or replacement of a contract of health insurance or health benefits, and ceding, securing, or placing a contract for reinsurance of risk relating to claims for health care (including stop-loss insurance and excess of loss insurance), provided that the requirements of Section 164.514 of the Regulations are met, if applicable;
-6-
|(4)
|
conducting or arranging for medical review, legal services, and auditing functions, including fraud and abuse detection and compliance programs;
|(5)
|
business planning and development, such as conducting cost-management and planning-related analyses related to managing and operating the Health Component, including development or improvement of methods of payment or coverage policies; and
|(6)
|
business management and general administrative activities of the Health Component, including, but not limited to management activities relating to implementation of and compliance with the requirements of the Act and the Regulations; Health Component participant service activities, including the provision of data analyses, provided that protected health information is not disclosed unless such disclosure is permissible under the Act and the Regulations; resolution of internal grievances; consistent with the applicable requirements of Section 164.514 of the Regulations, creation of deidentified health information.
|(1)
|
determinations of eligibility or coverage (including coordination of benefits or the determination of cost sharing amounts), and adjudication or subrogation of health benefit claims;
-7-
|(2)
|
risk adjusting amounts due based on enrollee health status and demographic characteristics;
|(3)
|
billing, claims management, collection activities, obtaining payment under a contract for reinsurance (including stop-loss insurance and excess of loss insurance), and related health care data processing;
|(4)
|
review of health care services with respect to medical necessity, coverage under the Health Component, appropriateness of care, or justification of charges;
|(5)
|
utilization review activities, including precertification and preauthorization of services, concurrent and retrospective review of services; and
|(6)
|
disclosure to consumer reporting agencies of any of the following protected health information relating to collection of premiums or reimbursement: name and address; date of birth; social security number; payment history; account number; and name and address of the health care provider and/or the Health Component.
|(C)
|
In the event that any person described in item (A) of this section fails to comply with any of the requirements of this section or of section 14.5 above, the noncompliance shall be reported to the Plan’s Privacy Officer in a report describing the name of the noncompliant person and a summary of the details regarding such person’s noncompliance. Upon receipt of such report, the Plan’s Privacy Officer shall solicit a response from the person who has been reported as noncompliant giving such person the opportunity to contest the charge of noncompliance or to offer justification or other reasons why sanctions should not be imposed with respect to the noncompliance. The Plan’s Privacy Officer shall, after considering all details and facts and circumstances relating to an alleged act of
-8-
|
noncompliance for which sanctions may be imposed pursuant to this item (C), determine if a sanction should be imposed (which sanction may range from a warning that subsequent acts of noncompliance may result in significant penalties to proposed dismissal from employment or termination of contract, as applicable). Upon determination of a sanction and if the sanction may be imposed under the authority of the Plan’s Privacy Officer, the sanction shall be imposed. If the sanction requires action of the Employer, the Plan’s Privacy Officer shall confer with the appropriate executives of the Employer. If the Employer, following consideration of a proposed sanction from the Plan’s Privacy Officer for noncompliance with the requirements of sections 14.5 and 14.6 by a person or entity, determines not to impose such sanction, the Employer shall advise the Plan’s Privacy Officer. In such event, the Plan’s Privacy Officer must consider and propose an alternative sanction for the noncompliant person or entity.
|(A)
|
To develop and propose to the Plan fiduciaries a protected health information policy for the Plan, which policy when adopted shall become the Privacy Policy.
|(B)
|
To provide development guidance and assist in the identification, implementation, and maintenance of information privacy policies and procedures in coordination with management and administration, and legal counsel.
-9-
|(C)
|
To perform initial and periodic information privacy risk assessments and conduct related ongoing compliance monitoring activities in coordination with information privacy compliance and operational assessment functions.
|(D)
|
To work with legal counsel and management, key departments, and committees to ensure the Employer has and maintains appropriate privacy and confidentiality consent, authorization forms, and information notices and materials reflecting current organization and legal practices and requirements.
|(E)
|
To oversee, direct, deliver or ensure delivery of initial and privacy training and orientation to all individuals in the Employer’s workforce who may have access to PHI in connection with the Plan.
|(F)
|
To participate in the development, implementation, and ongoing compliance monitoring of all trading partner and business associate agreements as a means of ensuring that all privacy concerns, requirements, and responsibilities are addressed.
|(G)
|
To track and monitor access to PHI within the Employer in connection with the operation and administration of the Plan and its sponsorship by the Employer.
|(H)
|
To establish rules to determine when to allow qualified individuals to review or receive a report on PHI privacy activity.
|(I)
|
To work cooperatively with the Human Resources Department and other applicable Employer offices/personnel in overseeing Plan Participants’ rights to inspect, amend and restrict access to PHI when appropriate.
|(J)
|
To establish and administer a process for receiving, documenting, tracking, investigating and taking action on all complaints concerning privacy policies and procedures in coordination and collaboration with other similar functions and, when necessary, with legal counsel.
|(K)
|
To ensure compliance with privacy practices and consistent application of sanctions for failure to comply with Plan privacy policies for all individuals in the Employer’s workforce.
-10-
|(L)
|
To initiate, facilitate and promote activities to foster information privacy awareness within the Employer.
|(M)
|
To review all system-related information security plans throughout the Employer’s network to ensure alignment between security and privacy practices and to act as a liaison to the information systems department.
|(N)
|
To work with all Employer personnel and Business Associates to ensure full coordination and cooperation under the Plan’s privacy policies and procedures and legal requirements.
|(O)
|
To maintain current knowledge of applicable federal and state privacy laws and monitor advancements in information privacy technologies to ensure organizational adaptation and compliance.
-11-
-12-
|•
|
Participating Employers: Dynegy Northeast Generation, Inc.
|•
|
Constituent Benefit Plan Documents: Summary Plan Description, Insurance Contract with Prudential Insurance Company (the “Prudential Contract”) and Dynegy Northeast Generation, Inc. Disability Plan.
-13-
|•
|
Plan Administrator: With respect to long term disability benefits provided or administered under the Prudential Contract, Prudential Insurance Company shall serve as benefit claims and benefit appeals fiduciary for the Dynegy Northeast Generation, Inc. Long Term Disability Plan and shall have the following powers, duties and responsibilities:
|(1)
|
The sole discretionary authority to interpret and decide all matters of fact and Plan interpretation in granting or denying long term disability benefits under the Prudential Contract, such interpretation decision thereof to be final and conclusive on all persons claiming benefits under the Prudential Contract;
|(2)
|
The sole discretionary authority to determine and authorize payment of long term disability benefits under the Prudential Contract, any such decision thereof to be final and conclusive on all persons;
|(3)
|
The sole discretionary authority to process and determine benefit claims and benefit claims appeals under the Prudential Contract except to the extent the Plan’s claims procedures expressly provides otherwise; and
|(4)
|
Any such other powers and duties as the Company shall designate to be its fiduciary responsibility with respect to the Dynegy Northeast Generation, Inc. Long Term Disability Plan.
|(1)
|
The sole discretionary authority to interpret and decide all matters of fact and Plan interpretation in granting or denying benefits under the Dynegy Northeast Generation, Inc. Disability Plan, such interpretation decision thereof to be final and conclusive on all persons claiming benefits under the Plan with respect to the Dynegy Northeast Generation, Inc. Disability Plan;
-14-
|(2)
|
The sole discretionary authority to determine and authorize payment of medical benefits under the Dynegy Northeast Generation, Inc. Disability Plan, any such decision thereof to be final and conclusive on all persons;
|(3)
|
The sole discretionary authority to process and determine benefit claims and benefit claims appeals under the Dynegy Northeast Generation, Inc. Disability Plan except to the extent the Plan’s claims procedures expressly provides otherwise; and
|(4)
|
In its sole discretionary authority, to determine eligibility under the terms of the Dynegy Northeast Generation, Inc. Long Term Disability Plan, its decision thereof to be final and conclusive on all persons;
|(5)
|
To prepare and distribute information explaining the Dynegy Northeast Generation, Inc. Long Term Disability Plan including, but not limited to, all materials and information required to be distributed pursuant to ERISA;
|(6)
|
To perform any and all reporting and disclosure required with respect to the Dynegy Northeast Generation, Inc. Long Term Disability Plan under applicable provisions of ERISA;
|(7)
|
To sue or cause suit to be brought in the name of the Plan with respect to the Dynegy Northeast Generation, Inc. Long Term Disability Plan;
|(8)
|
To correct any defect or supply any omission or recover any inconsistency that may appear in the Constituent Benefit Plan documents with respect to the Dynegy Northeast Generation, Inc. Long Term Disability Plan, in such manner and to such extent as it deems expedient; and
|(9)
|
To employ and compensate such accountants, attorneys and other agents and employees as it may deem necessary or advisable in the appropriate and efficient administration of the Plan with respect to the Dynegy Northeast Generation, Inc. Long Term Disability Plan,”
-15-
|DYNEGY NORTHEAST GENERATION, INC.
|By:
|/s/ [ILLEGIBLE]
|Title: Chairman, BPC
-16-
|1.
|
Individuals employed by or providing services to the division of the Employer’s Human Resources Department that deals with the administration and processing of benefit claims under the Health Components;
|2.
|
The Benefit Plans Committee;
|3.
|
The Privacy Officer;
|4.
|
The Contact Person;
|5.
|
Personnel in the Employer’s payroll and information systems departments who may receive information as to whether an individual is enrolled in the Plan or has disenrolled;
|6.
|
Effective as of April 20, 2005, the Security Officer.