I.
To delete the language in Section 6.0, Term of Contract, in its entirety and replace it with the following language:
Initial Term:
July 18, 2005 – June 30, 2006
Renewal Option 1:
July 1, 2006 – June 30, 2007
Renewal Option 2:
July 1, 2007 – June 30, 2008
Renewal Option 3:
July 1, 2008 – June 30, 2009
Renewal Option 4:
July 1, 2009 – June 30, 2010
Renewal Option 5:
July 1, 2010 – June 30, 2011
Renewal Option 6:
July 1, 2011 – June 30, 2012
Renewal Option 7:
July 1, 2012 – June 30, 2013
Renewal Option 8:
July 1, 2013 – June 30, 2014
Renewal Option 9:
July 1, 2014 – June 30, 2015
Renewal Option 10:
July 1, 2015 – June 30, 2016
Amendment #16
Page 1 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
II.
To replace Attachment E, Business Associate Agreement, with the revised version of that agreement that is contained at Exhibit 1 to this Amendment.
III.
This Amendment is contingent upon receiving approval from both CMS and DOAS and shall be effective once written notices of such approvals are received by DCH. DCH shall notify Contractor in writing upon receipt of responses from CMS and DOAS. In the event approval is denied by either CMS or DOAS, this Amendment shall be null and void and have no effect upon the Contract.
IV.
DCH and Contractor agree that they have assumed an obligation to perform the covenants, agreements, duties, and obligations of the Contract, as modified and amended herein, and agree to abide by all the provisions, terms and conditions contained in the Contract as modified and amended.
V.
This Amendment shall be binding and inure to the benefit of the Parties hereto, their heirs, representatives, successors, and assigns. In the event of a conflict between the provisions of this Amendment and the Contract or any previous amendments, the provisions of this Amendment shall control and govern. Additionally, in the event of a conflict between this Amendment and any exhibit or attachment incorporated into this Amendment, the provisions of this Amendment shall control and govern.
VI.
It is understood by the Parties hereto that, if any part, term, or provision of this Amendment or this Amendment in its entirety is held to be illegal or in conflict with any law of this State, then DCH, at its sole option, may enforce the remaining unaffected portions or provisions of this Amendment or of the Contract and the rights and obligations of the Parties shall be construed and enforced as if the Contract or Amendment did not contain the particular part, term or provision held to be invalid.
VII.
This Amendment shall be construed in accordance with the laws of the State of Georgia.
VIII.
All other terms and conditions contained in the Contract and any amendment thereto, not amended by this Amendment, shall remain in full force and effect.
IX.
Each Party has had the opportunity to be represented by counsel of its choice in negotiating this Amendment. This Amendment shall therefore be deemed to have been negotiated and prepared at the joint request, direction, and consideration of the Parties, at arms’ length, with the advice and participation of counsel, and will be interpreted in accordance with its terms without favor to any Party.
Amendment #16
Page 2 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
X.
This amendment may be signed in any number of counterparts, each of which shall be an original, with the same effect as if the signatures thereto were upon the same instrument Any signature below that is transmitted by facsimile or other electronic means shall be binding and effective as the original.
Amendment #16
Page 3 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
/s/ Clyde L. Reese, III
March 5, 2014
Clyde L. Reese III, Esq., Commissioner
Date
/s/ Jerry L. Dubberly
3/4/14
Jerry Dubberly, Chief
Date
Division of Medical Assistance Plans
BY:
/s/ Roman T. Kulich
2/27/14
*SIGNATURE
Date
Roman T. Kulich
Please Print/Type Name Here
TITLE President
Amendment #16
Page 4 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
1.
Terms used but not otherwise defined in this Agreement shall have the same meaning as those terms have in HIPAA and in Title XIII of the American Recovery and Reinvestment Act of 2009 (the Health Information Technology for Economic and Clinical Health Act, or “HITECH”), and in the implementing regulations of HIPAA and HITECH. Implementing regulations are published as the Standards for Privacy and Security of Individually Identifiable Health Information in 45 C.F.R. Parts 160 and 164. Together, HIPAA, HITECH, and their implementing regulations are referred to in this Agreement as the “Privacy Rule and Security Rule.” If the meaning of any defined term is changed by law or regulation, then this Agreement will be automatically modified to conform to such change. The term “NIST Baseline Controls” means the baseline controls set forth in National Institute of Standards and Technology (NIST) SP 800-53 established for “moderate impact” information.
2.
Except as limited in this Agreement, Contractor may use or disclose PHI only to the extent necessary to meet its responsibilities as set forth in the Contract provided that such use or disclosure would not violate the Privacy Rule or the Security Rule, if done by DCH. Furthermore, except as otherwise limited in this Agreement, Contractor may:
A.
Use PHI for internal quality control and auditing purposes.
B.
Use or disclose PHI as Required by Law.
C.
After providing written notification to DCH’s Office of Inspector General, use PHI to make a report to a health oversight agency authorized by law to investigate DCH (or otherwise
Amendment #16
Page 5 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
D.
Use and disclose PHI to consult with an attorney for purposes of determining Contractor’s legal options with regard to reporting conduct by DCH that Contractor in good faith believes to be unlawful, as permitted by 45 C.F.R. 164.502(j)(1).
3.
Contractor represents and warrants that only individuals designated by title or name on Attachments E-1 and E-2 will request PHI from DCH or access DCH PHI in order to perform the services of the Contract, and these individuals will only request the minimum necessary amount of information necessary in order to perform the services.
4.
Contractor represents and warrants that the individuals listed by title on Attachment E-1 require access to PHI in order to perform services under the Contract. Contractor agrees to send updates to Attachment E-1 whenever necessary. Uses or disclosures of PHI by individuals not described on Attachment E-1 are impermissible.
5.
Contractor represents and warrants that the individuals listed by name on Attachment E-2 require access to a DCH information system in order to perform services under the Contract. Contractor agrees to notify the Project Leader and the Access Control Coordinator named on Attachment E-2 immediately, but at least within 24 hours, of any change in the need for DCH information system access by any individual listed on Attachment E-2. Any failure to report a change within the 24 hour time period will be considered a security incident and may be reported to Contractor’s Privacy and Security Officer, Information Security Officer and the Georgia Technology Authority for proper handling and sanctions.
6.
Contractor agrees that it is a Business Associate to DCH as a result of the Contract, and represents and warrants to DCH that it complies with the Privacy Rule and Security Rule requirements that apply to Business Associates and will continue to comply with these requirements. Contractor further represents and warrants to DCH that it maintains and follows written policies and procedures to achieve and maintain compliance with the HIPAA Privacy and Security Rules that apply to Business Associates, including, but not limited to policies and procedures addressing HIPAA’s requirements that Business Associates use, request and disclose only the minimum amount of PHI necessary to perform their services, and updates such policies and procedures as necessary in order to comply with the HIPAA Privacy and Security Rules that apply to Business Associates and will continue to maintain and update such policies and procedures. These policies and procedures, and evidence of their implementation, shall be provided to DCH upon request.
7.
The Parties agree that a copy of all communications related to compliance with this Agreement will be forwarded to the following Privacy and Security Contacts:
Amendment #16
Page 6 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
A.
At DCH:
Kori Woodward-Dickens
HIPAA Privacy and Security Specialist, Office of General Counsel
hipaa@dch.ga.gov
kdickens@dch.ga.gov
404-651-5016
Sherman Harris
Agency Information Security Officer
sheharris@dch.ga.gov
404-656-9653
At Contractor:
Michael Yount
Chief Privacy/Security Officer
Michael.Yount@wellcare.com
813-206-5282
A.
Not request, create, receive, use or disclose PHI other than as permitted or required by this Agreement, the Contract, or as required by law.
B.
Establish, maintain and use appropriate administrative, physical and technical safeguards to prevent use or disclosure of the PHI other than as provided for by this Agreement or the Contract. Such safeguards must include an Information Security Program which consists of internal policies, standards and procedures built on the HIPAA Security Rules and the CMS HIPAA Security Series, unless DCH has agreed in writing that the control is not appropriate or applicable.
C.
Implement and use administrative, physical and technical safeguards that reasonably and appropriately protect the confidentiality, integrity and availability of the electronic protected health information that it creates, receives, maintains, or transmits on behalf of DCH. Such safeguards must include an Information Security Program which consists of internal policies, standards and procedures built on the HIPAA Security Rules and the CMS HIPAA Security Series, unless DCH has agreed in writing that the control is not appropriate or applicable.
D.
Implement the HITRUST Common Security Framework (CSF) by first quarter 2015;
E.
In addition to the safeguards described above, Contractor shall include access controls that restrict access to PHI to the individuals listed on E-1 and E-2, as amended from time to time, shall implement encryption of all electronic PHI during transmission and will use the following safeguards to protect PHI at rest:
(1)
Perimeter and multi-layer DMZ firewalls;
(2)
Intrusion Prevention Systems (IPS);
(3)
Data Loss Prevention (DLS) tools for Network and End-Point;
Amendment #16
Page 7 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
(4)
End-Point Protection (this includes host firewall, host IPS, Anti-virus and Malware protection, and full disk encryption for laptops)
(5)
Network Access Controls (NAC)
(6)
Web and Spam Filtering
(7)
Anti-virus/Malware Protection (email)
(8)
Database encryption
(9)
Centralized Logging and Monitoring Solution
(10)
Access Control Lists (this includes the following levels (1) File, Folder Share Level, (2) Database Level, and (3) Application Level)
F.
Upon DCH’s reasonable request, but no more frequently than annually, obtain an independent assessment of Contractor’s implementation of the HITRUST Common Security Framework (CSF) and the additional safeguards required by this Agreement with respect to DCH PHI, provide the results of such assessments to DCH, and ensure that corrective actions identified during the independent assessment are implemented.
G.
Mitigate, to the extent practicable, any harmful effect that may be known to Contractor from a use or disclosure of PHI by Contractor in violation of the requirements of this Agreement, the Contract or applicable regulations. Contractor shall bear the costs of mitigation, which shall include the reasonable costs of credit monitoring and may include credit restoration, if applicable, when the use or disclosure results in exposure of information commonly used in identity theft.
H.
Maintain a business associate agreement with its agents or subcontractors to whom it provides PHI, in accordance with which such agents or subcontractors are contractually obligated to comply with at least the same obligations that apply to Contractor under this Agreement, and ensure that its agents or subcontractors comply with the conditions, restrictions, prohibitions and other limitations regarding the request for, creation, receipt, use or disclosure of PHI, that are applicable to Contractor under this Agreement and the Contract.
I.
Report to DCH any use or disclosure of PHI that is not provided for by this Agreement or the Contract of which it becomes aware.
J.
Make an initial report to the DCH in writing in such form as DCH may require within three (3) business days after Contractor (or any subcontractor) becomes aware of the unauthorized use or disclosure. This report will require Contractor to identify the following:
i.
The nature of the impermissible use or disclosure (the “incident”), which will include a brief description of what happened, including the date it occurred and the date Contractor discovered the incident;
ii.
The Protected Health Information involved in the impermissible use or disclosure, such as whether the full name, social security number, date of birth, home address, account number or other information were involved);
Amendment #16
Page 8 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
iii.
Who (by title, access permission level and employer) made the impermissible use or disclosure and who received the Protected Health Information as a result;
iv.
What corrective or investigational action Contractor took or will take to prevent further impermissible uses or disclosures, to mitigate harmful effects, and to prevent against any further incidents;
v.
What steps individuals who may have been harmed by the incident might take to protect themselves; and
vi.
Whether Contractor believes that the impermissible use or disclosure constitutes a Breach of Unsecured Protected Health Information.
K.
Report to the DCH HIPAA Privacy and Security Officer and the DCH Agency Information Security Officer any successful unauthorized access, modification, or destruction of PHI or interference with system operations in Contractor’s information systems as soon as practicable but in no event later than three (3) business days of discovery. If such a security incident resulted in a use or disclosure of PHI not permitted by this Agreement, Contractor shall also make a report of the impermissible use or disclosure as described above. Contractor agrees to make a complete report to the DCH in writing within two weeks of the initial report that includes a root cause analysis and, if appropriate, a proposed corrective action plan designed to protect PHI from similar security incidents in the future. Upon DCH’s approval of Contractor’s corrective action plan, Contractor agrees to implement the corrective action plan and provide proof of implementation to the DCH.
L.
Upon DCH’s reasonable request and not more frequently than once per quarter, report to the DCH Agency Information Security Officer any (A) attempted (but unsuccessful) unauthorized access, use, disclosure, modification, or destruction of PHI or (B) attempted (but unsuccessful) interference with system operations in Contractor’s information systems. Contractor does not need to report trivial incidents that occur on a daily basis, such as scans, “pings,” or other routine attempts that do not penetrate computer networks or servers or result in interference with system operations.
M.
Cooperate with DCH and provide assistance necessary for DCH to determine whether a Breach of Unsecured Protected Health Information has occurred, and whether notification of the Breach is legally required or otherwise appropriate. Contractor agrees to assist DCH in its efforts to comply with the HIPAA Privacy and Security Rules, as amended from time to time. To that end, the Contractor will abide by any requirements mandated by the HIPAA Privacy and Security Rules or any other applicable laws in the course of this Contract. Contractor warrants that it will cooperate with DCH, including cooperation with DCH privacy officials and other compliance officers required by the HIPAA Privacy and Security Rules
Amendment #16
Page 9 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
N.
If DCH determines that a Breach of Unsecured Protected Health Information has occurred as a result of Contractor’s impermissible use or disclosure of PHI or failure to comply with obligations set forth in this Agreement or in the Privacy or Security Rules, provide all notifications to Individuals, HHS and/or the media, on behalf of DCH, after the notifications are approved by the DCH. Contractor shall provide these notifications in accordance with the security breach notification requirements set forth in 42 U.S.C. §17932 and 45 C.F.R. Parts 160 & 164 subparts A, D & E as of their respective Compliance Dates, and shall pay for the reasonable and actual costs associated with such notifications.
O.
Make any amendment(s) to PHI in a Designated Record Set that DCH directs or agrees to pursuant to 45 CFR 164.526 within five (5) business days after request of DCH. Contractor also agrees to provide DCH with written confirmation of the amendment in such format and within such time as DCH may require.
P.
In order to meet the requirements under 45 CFR 164.524, regarding an individual’s right of access, Contractor shall, within five (5) business days following DCH’s request, or as otherwise required by state or federal law or regulation, or by another time as may be agreed upon in writing by the DCH, provide DCH access to the PHI in an individual’s Designated Record Set. However, if requested by DCH, Contractor shall provide access to the PHI in a Designated Record Set directly to the individual to whom such information relates.
Q.
Give the Secretary of the U.S. Department of Health and Human Services (the “Secretary”) or the Secretary’s designees access to Contractor’s books and records and policies, practices or procedures relating to the use and disclosure of PHI for or on behalf of DCH within five (5) business days after the Secretary or the Secretary’s designees request such access or otherwise as the Secretary or the Secretary’s designees may require. Contractor also agrees to make such information available for review, inspection and copying by the Secretary or the Secretary’s designees during normal business hours at the location or locations where such information is maintained or to otherwise provide such information to the Secretary or the Secretary’s designees in such form, format or manner as the Secretary or the Secretary’s designees may require.
R.
Document all disclosures of PHI and information related to such disclosures as would be required for DCH to respond to a request by an Individual or by the Secretary for an accounting of disclosures of PHI in accordance with 45 C.F.R. § 164.528. By no later than five (5) business days of receipt of a written request from DCH, or as otherwise required by state or federal law or regulation, or by another time as may be agreed upon in writing by the DCH
Amendment #16
Page 10 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
S.
In addition to any indemnification provisions in the Contract, indemnify the DCH from any liability resulting from any violation of the HIPAA Privacy and Security Rules or Breach that arises from the conduct or omission of Contractor or its employee(s), agent(s) or subcontractor(s). Such liability will include, but not be limited to, all actual and direct costs and/or losses, civil penalties and reasonable attorneys’ fees imposed on DCH.
T.
For any requirements in this Agreement that include deadlines, pay performance guarantee payments of $300.00 per calendar day, starting with the day after the deadline and continuing until Contractor complies with the requirement. Contractor shall ensure that its agreements with subcontractors enable Contractor to meet these deadlines.
8.
DCH agrees that it will:
A.
Notify Contractor of any new limitation in the applicable Notice of Privacy Practices in accordance with the provisions of the Privacy Rule if, and to the extent that, DCH determines in the exercise of its sole discretion that such limitation will affect Contractor’s use or disclosure of PHI.
B.
Notify Contractor of any change in, or revocation of, authorization by an Individual for DCH to use or disclose PHI to the extent that DCH determines in the exercise of its sole discretion that such change or revocation will affect Contractor’s use or disclosure of PHI.
C.
Notify Contractor of any restriction regarding its use or disclosure of PHI that DCH has agreed to in accordance with the Privacy Rule if, and to the extent that, DCH determines in the exercise of its sole discretion that such restriction will affect Contractor’s use or disclosure of PHI.
D.
Prior to agreeing to any changes in or revocation of permission by an Individual, or any restriction, to use or disclose PHI, DCH agrees to contact Contractor to determine feasibility of compliance. DCH agrees to assume all costs incurred by Contractor in compliance with such special requests.
9.
The Term of this Agreement shall be effective on the Effective Date and shall terminate when all of the PHI provided by DCH to Contractor, or created or received by Contractor on behalf of DCH, is destroyed or returned to DCH, or, if it is infeasible to return or destroy PHI, protections are extended to such information, in accordance with the termination provisions in this section.
A.
Termination for Cause. Upon DCH’s knowledge of a material breach of this Agreement by Contractor, DCH shall either:
i.
Provide an opportunity for Contractor to cure the breach of Agreement within a reasonable period of time, which shall be within thirty (30) calendar days after receiving written notification of the breach by DCH;
Amendment #16
Page 11 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
ii.
If Contractor fails to cure the breach of Agreement, terminate the Contract upon thirty (30) calendar days notice; or
iii.
If neither termination nor cure is feasible, DCH shall report the breach of Agreement to the Secretary of the Department of Health and Human Services.
B.
Effect of Termination.
i.
Upon termination of this Agreement, for any reason, DCH and Contractor shall determine whether return of PHI is feasible. If return of the PHI is not feasible, Contractor agrees to continue to extend the protections of this Agreement to the PHI for so long as the Contractor maintains the PHI and shall limit the use and disclosure of the PHI to those purposes that made return or destruction of the PHI infeasible. If at any time it becomes feasible to return or destroy any such PHI maintained pursuant to this paragraph, Contractor must notify DCH and obtain instructions from DCH for either the return or destruction of the PHI.
ii.
Contractor agrees that it will limit its further use or disclosure of PHI only to those purposes DCH may, in the exercise of its sole discretion, deem to be in the public interest or necessary for the protection of such PHI, and will take such additional actions as DCH may require for the protection of patient privacy and the safeguarding, security and protection of such PHI.
iii.
This Effect of Termination section survives the termination of the Agreement.
10.
Interpretation. Any ambiguity in this Agreement shall be resolved to permit DCH and Contractor to comply with applicable laws, rules and regulations, the HIPAA Privacy Rule, the HIPAA Security Rule and any rules, regulations, requirements, rulings, interpretations, procedures or other actions related thereto that are promulgated, issued or taken by or on behalf of the Secretary; provided that applicable laws, rules and regulations and the laws of the State of Georgia shall supersede the Privacy Rule if, and to the extent that, they impose additional requirements, have requirements that are more stringent than or have been interpreted to provide greater protection of patient privacy or the security or safeguarding of PHI than those of the HIPAA Privacy Rule.
11.
No Third Party Beneficiaries. Nothing express or implied in this Agreement is intended to confer, nor shall anything herein confer, upon any person other than the Parties and the respective successors or assigns of the Parties, any rights, remedies, obligations or liabilities whatsoever.
12.
All other terms and conditions contained in the Contract and any amendment thereto, not amended by this Agreement, shall remain in full force and effect.
Amendment #16
Page 12 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
BY:
/s/ Roman T. Kulich
2/27/14
SIGNATURE
Date
Roman T. Kulich
President
TITLE*
Amendment #16
Page 13 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
•
Annette Zerbe – Regulatory Affairs
•
Joshua Luft – Reporting & Analytics
•
James Johnson – IT & Operations
•
Franklin Moultrie – Project Analysis
•
Avis Boswell – Project Administration
•
Secure FTP file transfer (preferred)
•
Encrypted email or email sent through “secure tunnel” approved by DCH Information Security Officer
•
Email of encrypted document (password must be sent by telephone only)
•
Encrypted portable media device and tracked delivery method
DCH Project Leader Contact Information:
Lynnette R. Rhodes
Deputy Director, Medicaid Operations
Georgia Department of Community Health
2 Peachtree St., NW – 36th Floor
Atlanta, Georgia 30303
(404) 656-7513
Amendment #16
Page 14 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.
_________
Contractor DOES NOT need any user accounts to access DCH Information Systems. Do not complete Part 2 of this form.
____X____
Contractor DOES need user accounts to access DCH Information Systems. Please complete Part 2 of this form.
Full Name
Employer
DCH Information System
Type of Access
(Read only? Write?)
Separate Attachment
DCH Project Leader Contact Information:
Lynnette R. Rhodes
Deputy Director, Medicaid Operations
Georgia Department of Community Health
2 Peachtree St., NW – 36th Floor
Atlanta, Georgia 30303
(404) 656-7513
Amendment #16
Page 15 of 15
Contract #0654
WELLCARE OF GEORGIA, INC.