St. Norbert College Health & Wellness Services Business Associate Policy Purpose: These contract terms satisfy our obligation under both the Health Insurance portability and Accountability Act of 1996 (HIPAA) and its implementing regulations issued by the U.S. Department of Health And Human services (45 CFR Parts 160-164) to ensure integrity and confidentiality of protected health information (PHI) that a business associate (BA) may create or receive for or from St. Norbert College Health Services. These contract terms must be used with each of our BA. A BA is any person or organization that we engage to perform or assist in performing functions or activities that involve use or disclosure of PHI created for or from St. Norbert College Health and Wellness Services. A BA is also any person or organization that provides legal, actuarial, accounting, consulting, data aggregation, management, administration, accreditation or financial services to or for St. Norbert College Health and Wellness Services and receives PHI from St. Norbert College or another BA of St. Norbert College. Procedure: Each BA associated with the St. Norbert College Health and Wellness Services will have a signed agreement related to the privacy policy of St. Norbert College Health Services (see Business Associate Addendum) June, 2014