Laserfiche WebLink
C. Applicability <br />This policy applies to all Virtru employees and Business Associate Subcontractors, which <br />are defined for the purposes of this document to be employees of all current and future <br />subsidiaries of Virtru and the Business Associate Subcontractor. <br />D. Policy <br />1. Generally: Virtru may disclose Personally -Identifiable Information to a Business <br />Associate Subcontractor, or allow a Business Associate Subcontractor to create or <br />receive PII on Virtru's behalf, if adequate assurances are obtained by Virtru that <br />the Business Associate Subcontractor will appropriately safeguard the PII. Virtru <br />must document these assurances through a written agreement. This requirement <br />does not apply with respect to: <br />a. Disclosures made to a provider concerning the individual's treatment, payment <br />or health care operations; or <br />b. Uses or disclosures made to a governmental agency for purposes of public <br />benefit eligibility or enrollment determinations where such company is <br />authorized by law to make these determinations. <br />2. Content Requirements: The agreement between Virtru and a Business Associate <br />Subcontractor must meet the following requirements, as applicable: <br />a. Establish permitted and required uses or disclosures of Personally -Identifiable <br />Information that are consistent with those authorized for the entity, except that <br />the agreement may permit the Business Associate Subcontractor to use or <br />disclose Personally -Identifiable Information for its own management and <br />administration if such use, or disclosure is required by law, or the Business <br />Associate Subcontractor obtains reasonable assurance from the entity to which <br />the Personally -Identifiable Information is disclosed that the confidentiality of <br />the PII will be maintained. <br />b. Provide that the Business Associate Subcontractor will: <br />1) Not use or disclose the Personally -Identifiable Information except as <br />authorized under the agreement or required by law. <br />2) Use safeguards to prevent unauthorized use or disclosure. <br />3) Report unauthorized uses or disclosures to Virtru. <br />4) Pass on the same obligations relating to protection of <br />Personally -Identifiable Information to any subcontractors or agents. <br />5) Make Personally -Identifiable Information available for access by Virtru, <br />in accordance with relevant law and policy. <br />15 <br />Rev.2015.8.25 <br />