BUSINESS ASSOCIATE AGREEMENT FOR SPECTRUM BUSINESS CONNECT WITH RINGCENTRAL SERVICE

This Agreement is made and entered into as of the effective date by and between Spectrum Business Customer (“Covered Entity”) and Charter Communications Operation, LCC Spectrum Business Connect with RingCentral Terms of Service (“Business Associate”) collectively are referred to herein individually as a “Party” and, collectively, as the “Parties”.

WHEREAS, Business Associate has been engaged to perform certain functions, activities, or services for or on behalf of Covered Entity that involve the use or disclosure of Protected Health Information (as defined herein) and Electronic Protected Health Information (as defined herein) pursuant to a separate agreement or agreements (the “Underlying Agreement(s)”); and

WHEREAS, this Agreement is intended to comply with the requirement for written assurances between the Parties as contemplated by the Standards for Privacy of Individually Identifiable Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and E, as may be amended from time to time (the “Privacy Rule”) and the Security Standards for Health Insurance Reform at 45 C.F.R. Parts 160, 162 and 164, as may be amended from time to time (the “Security Rule”); and

WHEREAS, the “Health Information Technology for Economic and Clinical Health” (“HITECH”) Act, contained within the American Recovery and Reinvestment Act of 2009 (Pub. L. No. 111-5, 123 Stat. 226), modifies the Privacy Rule and the Security Rule (hereinafter, all references to the Privacy Rule and the Security Rule shall include all amendments to such rules as may be published from time to time in connection with the HITECH Act, and all references to the HITECH Act shall include any accompanying regulations whether in effect as of the effective date of this Agreement or subsequently promulgated); and

NOW, THEREFORE, for and in consideration of the Parties’ continuing obligations under the existing agreement or agreements between the Parties, the agreements herein, and other good and valuable consideration, the receipt and sufficiency of which is hereby acknowledged, the Parties agree as follows:

1.         Definitions

Except as otherwise defined herein, any and all capitalized terms in this Agreement shall have the definitions set forth in the Privacy Rule or the Security Rule.

(A)             Breach” means the unauthorized acquisition, access, use or disclosure of Unsecured Protected Health Information which compromises the security or privacy of such information.  “Breach” excludes:

(i)        Any unintentional acquisition, access, or use of Protected Health Information by a workforce member or person acting under the authority of the Covered Entity or Business Associate, if such acquisition, access, or use was made in good faith and within the scope of authority and does not result in further use or disclosure in a manner not permitted under the Privacy Rule.

(ii)        Any inadvertent disclosure by a person who is authorized to access Protected Health Information at the Covered Entity or Business Associate to another person authorized to access Protected Health Information at the Covered Entity or Business Associate, if the information received as a result of such disclosure is not further used or disclosed in a manner not permitted under the Privacy Rule.

(iii)      A disclosure of Protected Health Information where the Covered Entity or Business Associate has a good faith belief that an unauthorized person to whom the disclosure was made would not reasonably have been able to retain such information.

Except in the event that one of the exclusions listed above applies, an acquisition, access, use or disclosure of Protected Health Information in a manner not permitted under the Privacy Rule is presumed to be a Breach unless the Covered Entity or Business Associate, as applicable, demonstrates that there is a low probability that the Protected Health Information has been compromised based on a risk assessment of at least the following factors:

(i)         The nature and extent of the Protected Health Information involved, including the types of identifiers and the likelihood of re-identification;

(ii)        The unauthorized person who used the Protected Health Information or to whom the disclosure was made;

(iii)       Whether the Protected Health Information was actually acquired or viewed; and

(iv)       The extent to which the risk to the Protected Health Information has been mitigated.

(B)              “Business Associate” has the meaning set forth above.

(C)              “Covered Entity” has the meaning set forth above.

(D)              “Designated Record Set” has the same meaning as the term “designated record set” in 45 C.F.R. § 164.501 of the Privacy Rule.

(E)             Electronic Protected Health Information” has the same meaning as the term “electronic protected health information” in 45 C.F.R. § 160.103 of the Security Rule, limited to the information created or received by Business Associate from or on behalf of the Covered Entity.

(F)             “Health Information Technology for Economic and Clinical Health (“HITECH”) Act” has the meaning set forth above.

(G)             “Individual” has the same meaning as the term “individual” in 45 C.F.R. § 160.103 of the Privacy Rule.

(H)              Privacy Rule” has the meaning set forth above.

(I)               Protected Health Information (“PHI”)” has the same meaning as the term “protected health information” in 45 C.F.R. § 160.103 of the Privacy Rule (including, without limitation, Electronic Protected Health  Information), limited to the information created or received by Business Associate from or on behalf of Covered Entity.

(J)              Required by Law” has the same meaning as the term “required by law” in 45 C.F.R. § 164.103 of the Privacy Rule.

(K)              Secretary” means the Secretary of the Department of Health and Human Services or his or her designee.

(L)             Security Incident” has the same meaning as the term “security incident” in 45 C.F.R. § 164.304 of the Security Rule.

(M)             Security Rule” has the meaning set forth above.

(N)             “Unsecured Protected Health Information” means Protected Health Information that is not rendered unusable, unreadable, or indecipherable to unauthorized persons through the use of a technology or    methodology specified by the Secretary in the guidance issued under section 13402(h)(2) of Public Law 111-5.

2.         Obligations and Activities of Business Associate

(A)             Business Associate acknowledges and agrees that all Protected Health Information that is created or received by Covered Entity and used by or disclosed to Business Associate or created or received by Business Associate on the Covered Entity’s behalf shall be subject to this Agreement. (B)              Business Associate agrees to not use or disclose Protected Health Information other than as permitted or required by this Agreement or as Required by Law. (C)              Business Associate agrees to use appropriate safeguards and comply, where applicable, with the Security Rule with respect to Electronic Protected Health Information to prevent use or disclosure of PHI other than as provided for by this Agreement. (D)             Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known to Business Associate of a use or disclosure of Protected Health Information by Business Associate in violation of the requirements of this Agreement, the Privacy Rule or the Security Rule. (E)             Business Associate agrees to promptly report to Covered Entity following discovery of (i) any use or disclosure of PHI not provided for by this Agreement or (ii) any Breach or Security Incident of which it becomes aware; provided that notice is hereby deemed given for attempted but Unsuccessful Security Incidents and no further notice of such Unsuccessful Security Incidents will be given. “Unsuccessful Security Incidents” include but are not limited to firewall pings and other broadcast attacks, port scans, unsuccessful log-on attempts, denial-of service attacks, and any combination of the foregoing that do not result in unauthorized access, acquisition, Use or Disclosure of PHI.  A Breach shall be treated as discovered by Business Associate as of the first day on which the Breach (i) is known to an employee, officer, or other agent of Business Associate, or (ii) by exercising reasonable diligence, would have been known to an employee, officer, or other agent of Business Associate.  The notice shall include, to the extent available, the identification of each individual whose Unsecured Protected Health Information has been, or is reasonably believed by Business Associate to have been, accessed, acquired, or disclosed during the Breach, as well as any other available information set forth in 45 C.F.R. § 164.404(c). (F)              Business Associate agrees to ensure that any subcontractor that creates, receives, maintains or transmits Protected Health Information on behalf of the Business Associate agrees in writing to the same restrictions and conditions that apply through this Agreement to Business Associate with respect to such information. (G)                 In response to a request by Covered Entity, Business Associate agrees to provide access to Protected Health Information maintained in a Designated Record Set, to Covered Entity in order to meet the requirements of 45 C.F.R. § 164.524. (H)                Business Associate does not maintain Protected Health Information as part of a Designated Record Set in connection with the services Business Associate provides to Covered Entity pursuant to the Underlying Agreement(s) between the Parties.  To the extent Covered Entity considers Protected Health Information to constitute part of a Designated Record Set, Covered Entity is responsible for downloading and maintaining the relevant Protected Health Information as part of such Designated Record Set. (I)              Business Associate agrees to document such disclosures of Protected Health Information and information related to such disclosures as would be required to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 C.F.R. § 164.528 and the HITECH Act. (J)              Business Associate agrees to provide to Covered Entity information collected in accordance with Section 2(I) of this Agreement, to respond to a request by an Individual for an accounting of disclosures of Protected Health Information in accordance with 45 C.F.R. § 164.528 and the HITECH Act. (K)             To the extent the Business Associate is to carry out Covered Entity’s obligations under the Privacy Rule, Business Associate agrees to comply with the requirements of the Privacy Rule that apply to Covered Entity in the performance of such obligation. (L)              Business Associate agrees to make internal practices, books, and records available to the Secretary, in a time and manner designated by the Secretary, for purposes of the Secretary determining Covered Entity’s compliance with the Privacy Rule or the Security Rule.

3.         Permitted Uses and Disclosures by Business Associate

(A)             Except as otherwise limited in this Agreement, Business Associate may use or disclose Protected Health Information to perform functions, activities or services for or on behalf of Covered Entity as contemplated by the Underlying Agreement(s) between the Parties, provided that such use or disclosure does not violate the Privacy Rule or the HITECH Act if done by Covered Entity. (B)              Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information for the proper management and administration of the Business Associate or to carry out the present and/or future legal responsibilities of the Business Associate. (C)              Except as otherwise limited in this Agreement, Business Associate may disclose Protected Health Information for the proper management and administration of the Business Associate, provided that disclosures are Required by Law, or Business Associate obtains reasonable assurances from the person to whom the information is disclosed that it will remain confidential and used or further disclosed only as Required by Law or for the purpose for which it was disclosed to the person, and the person notifies Business Associate of any instances of which it is aware in which the confidentiality of the information has been breached. (D)             Business Associate may use Protected Health Information to report violations of law to appropriate federal and state authorities, consistent with 45 C.F.R. § 164.502(j)(1). (E)              Except as otherwise limited in this Agreement, Business Associate may use Protected Health Information to aggregate data as permitted by 45 C.F.R. § 164.504(e)(2)(i)(B). (F)              Except as otherwise limited by this Agreement, Business Associate may use Protected Health Information to create de-identified information pursuant to the requirements set forth at 45 C.F.R. § 164.514(a)-(c).

4.         Obligations of Covered Entity on Behalf of Business Associate

(A)             Covered Entity shall notify Business Associate of any limitation(s) in its notice of privacy practices in accordance with 45 C.F.R. § 164.520, to the extent that such limitation(s) may affect Business Associate’s use or disclosure of Protected Health Information. (B)              Covered Entity shall notify Business Associate of any changes in, or revocation of, permission by an Individual to use or disclose Protected Health Information, to the extent that such changes may affect Business Associate’s use or disclosure of Protected Health Information. (C)              Covered Entity shall notify Business Associate of any restriction to the use or disclosure of Protected Health Information that it has agreed to in accordance with 45 C.F.R. § 164.522, to the extent that such restriction may affect Business Associate’s use or disclosure of Protected Health Information.

(D)             Covered Entity shall not request that Business Associate use or disclose Protected Health Information in any manner that would not be permissible under the Privacy Rule if done by Covered Entity.

5.         Term and Termination

(A)             *Term.*  The Term of this Agreement shall be effective as of the Effective Date, and shall continue until the earlier of termination of this Agreement as set forth below or until no Underlying Agreement is in effect between Covered Entity and Business Associate for Business Associate to perform activities or services for or on behalf of Covered Entity.  Upon the termination of all of such agreements between Covered Entity and Business Associate, this Agreement automatically terminates without notice.

(B)              Termination for Cause.  Upon the Covered Entity’s or Business Associate’s knowledge of a material breach or violation by Business Associate of any provision of this Agreement, the Covered Entity shall either:

(i)       Provide an opportunity for Business Associate to cure the breach or end the violation and terminate this Agreement and any other agreement between the Parties which involves the use or disclosure of Protected Health Information if Business Associate does not cure the breach or end the violation within the time specified by Covered Entity;

(ii)       Immediately terminate this Agreement and any other agreement between the Parties which involves the use or disclosure of Protected Health Information if Business Associate has breached or  violated a material term of this Agreement and cure is not possible; or

(iii)       If neither termination nor cure is feasible, Covered Entity shall report the violation to the Secretary.

(C)             Effect of Termination.  Business Associate shall, if feasible, return or destroy all Protected Health Information received from Covered Entity, or created or received by Business Associate for or on behalf of Covered Entity.  If it is infeasible to return or destroy any portions of the Protected Health Information upon termination of this Agreement, then Business Associate shall (1) provide to Covered Entity notification of the conditions that make returns or destruction infeasible, and (2) extend the protections of this Agreement to such information, and limit further uses and disclosures of such Protected Health Information to those purposes that make the return or destruction infeasible, for so long as Business Associate maintains such Protected Health Information.  This provision shall apply to Protected Health Information that is in the possession of Subcontractors or agents of Business Associate.

6.         Notification

With respect to notice pursuant to paragraph 2(E) above, notice shall be made to the contact information on record for Covered Entity’s account, followed promptly by a written notice as described below.

Any notice required or provided for under this Agreement shall be made in writing and shall be either personally delivered, mailed by first class mail, sent via facsimile or sent via electronic mail to the appropriate individual identified below.

For Covered Entity:                                    Notice shall be made to the contact of record for

Covered Entity’s account.

For Business Associate:                           Charter Communications Operating, LLC
                                                                     ATTN: Legal Operations - Commercial Contracts       12405 Powerscourt Dr.

St. Louis, MO 63131

Either Party may designate a different address in writing to the other.

7.         Regulatory References

A reference in this Agreement to a section in the Privacy Rule, the Security Rule or the HITECH Act means the section as in effect or as amended.

8.         Amendment

The Parties agree to take such action as is necessary to amend this Agreement from time to time as is necessary for Covered Entity to comply with the requirements of the Health Insurance Portability and Accountability Act of 1996, the Privacy Rule, the Security Rule and the HITECH Act, as amended.

9.         Survival

The respective rights and obligations of the Business Associate under Section 5 of this Agreement shall survive the termination of this Agreement.

10.       Interpretation

Any ambiguity in this Agreement shall be resolved to permit compliance with the Privacy Rule, the Security Rule and the HITECH Act.  Any conflict between the terms of this Agreement and any other agreement relating to the same subject matter, which is the Business Associate requirements under the Privacy Rule, the Security Rule and the HITECH Act, shall be resolved so that the terms of this Agreement supersede and replace the relevant terms of any such other agreement.

11.         Anti-Assignment

Neither Party may assign either this Agreement or any of its rights, interests or obligations hereunder without the prior written approval of the other party.

12.         Counterparts

This Agreement may be executed in counterparts which, when all signatures are assembled, shall have the same effect as a single, fully-executed agreement.  Facsimile and photocopy signatures shall have the same binding effect as manual signatures.

13.         Severability

The provisions of this Agreement shall be severable, and if any provision of this Agreement shall be held or declared to be illegal, invalid or unenforceable, the remainder of this Agreement shall continue in full force and effect as though such illegal, invalid or unenforceable provision had not been contained herein.

14.         Governing Law

Except to the extent that the Privacy Rule, the Security Rule, the HITECH Act or other federal law applies, this Agreement and the obligations of the Parties hereunder will be governed by interpreted in accordance with the laws of the State of New York, without reference to the choice of law principles thereof.  Each Party agrees to be subject to personal jurisdiction in the federal and state courts of the State of New York.  The exclusive jurisdiction and venue for any dispute arising out of or in connection with this Agreement shall be in the federal or state courts of the State of New York located in the Southern District of New York or New York County, as applicable.