Appropriate Safeguards BA shall implement appropriate safeguards to prevent the use or disclosure of Protected Information other than as permitted by the Contract or Addendum, including, but not limited to, administrative, physical and technical safeguards in accordance with the Security Rule, including, but not limited to, 45 C.F.R. Sections 164.308, 164.310, and 164.312. [45 C.F.R. Section 164.504(e)(2)(ii)(B); 45 C.F.R. Section 164.308(b)]. BA shall comply with the policies and procedures and documentation requirements of the Security rule, including, but not limited to, 45 C.F.R. Section 164.316 [42 U.S.C. Section 17931].
Information Access Each Party (“Disclosing Party”) shall make available to another Party (“Requesting Party”) information that is in the possession of the Disclosing Party and is necessary in order for the Requesting Party to: (i) verify the costs incurred by the Disclosing Party for which the Requesting Party is responsible under this Agreement; and (ii) carry out its obligations and responsibilities under this Agreement. The Parties shall not use such information for purposes other than those set forth in this Article 25.1 of this Agreement and to enforce their rights under this Agreement.
Receiving Party Personnel The receiving Party will limit access to the Confidential Information of the disclosing Party to those of its employees, attorneys and contractors that have a need to know such information in order for the receiving Party to exercise or perform its rights and obligations under this Agreement (the “Receiving Party Personnel”). The Receiving Party Personnel who have access to any Confidential Information of the disclosing Party will be made aware of the confidentiality provision of this Agreement, and will be required to abide by the terms thereof. Any third party contractors that are given access to Confidential Information of a disclosing Party pursuant to the terms hereof shall be required to sign a written agreement pursuant to which such Receiving Party Personnel agree to be bound by the provisions of this Agreement, which written agreement will expressly state that it is enforceable against such Receiving Party Personnel by the disclosing Party.
Passwords and Employee Access Provider shall secure usernames, passwords, and any other means of gaining access to the Services or to Student Data, at a level suggested by Article 4.3 of NIST 800-63-3. Provider shall only provide access to Student Data to employees or contractors that are performing the Services. Employees with access to Student Data shall have signed confidentiality agreements regarding said Student Data. All employees with access to Student Records shall pass criminal background checks.
Employee Access Employees are entitled to read and review their personnel file and, without limiting the generality of the foregoing, shall be entitled to inspect their performance evaluations, written censures, letters of reprimand, and other adverse reports. Upon request, employees shall be given copies of all such pertinent documents. The Employer further agrees that no personal files or documents on employees shall be kept outside of the personnel file, apart from payroll or health services files.