DIAGNOSTIC TEST PURCHASE AGREEMENT
Lab: Viome Life Sciences, Inc. ("Viome")
10800 NE 8th St. Suite 910
Bellevue, Washington 98004
Practice (Legal Entity) ("Practice")
Version 2.1
Current as of June 20, 2026
AGREEMENT TERMS AND CONDITIONS
1. PURPOSE AND SCOPE
This Diagnostic Test Purchase Agreement including the Business Associate Agreement (“BAA”) incorporated therein ("Agreement") establishes the terms under which Viome supplies diagnostic tests to Practice for use with Practice's patients on a private-pay basis. This Agreement governs the purchase and use of Viome Pro Solution Tests & Services (“Tests” or “Test Kits”) listed on the Products & Service Addendum (“Addendum”) that appears at the end of this Agreement and as identified in each Order Form or as ordered via Practice's Shopify account. Each Order Form is incorporated into this Agreement by reference. This is a non-exclusive arrangement; Practice has no right to distribute Tests to other practices or third-party resellers.
2. ELECTRONIC ACCEPTANCE
Practice agrees that this Agreement may be presented and accepted electronically through the Viome Provider Portal (“Provider Portal”, “Practice Portal”, or "Portal"). By clicking the "Agree & Continue" button, checking any acceptance box, accessing the Provider Portal, ordering Tests, or otherwise using the Services after being presented with this Agreement, Practice:
(a) acknowledges that it has reviewed and had an opportunity to review this Agreement;
(b) agrees to be bound by this Agreement on behalf of Practice;
(c) consents to the use of electronic signatures, electronic records, and electronic contract formation; and
(d) agrees that electronic records maintained by Viome regarding acceptance of this Agreement, including date, time, IP address, user account information, and acceptance logs, shall constitute admissible evidence of execution and acceptance.
The Parties agree that this Agreement is enforceable under the U.S. Electronic Signatures in Global and National Commerce Act (E-SIGN), the Uniform Electronic Transactions Act (UETA), and other applicable laws governing electronic contracts.
.
3. TERM AND RENEWAL
This Agreement commences on the Effective Date (as defined below) and continues for three (3) years (the "Initial Term"). It then auto-renews for successive one (1)-year terms unless either party gives sixty (60) days' written non-renewal notice before the applicable term ends (“Renewal Term”). This Agreement remains in effect for the Initial Term and any Renewal Terms (collectively, “Term”) as specified herein.
Effective Date. This Agreement becomes effective on the date an authorized representative of the Practice electronically accepts this Agreement through the Portal by clicking "Agree & Continue" or otherwise indicating acceptance of this Agreement (the "Effective Date"). No further signature by Viome shall be required. Viome's provision of access to the Provider Portal, acceptance of orders, or provision of Viome Services shall constitute Viome's acceptance of this Agreement.
During the Renewal Terms, Viome reserves the right to modify pricing at its discretion, provided that any price increase shall not exceed fifteen percent (15%) and Viome provides Practice with at least sixty (60) days' advance written notice of such price increase prior to the renewal date. Practice may terminate this Agreement without penalty within thirty (30) days of receiving notice of a price increase by providing written notice to Viome.
4. ORDERING AND TEST KIT PROVISION
Tests may be ordered via the Viome Provider Portal or by contacting the Viome Account Executive (“Account Executive”). Viome ships Test Kits to the ship-to address specified in the applicable Order Form or Portal order, or, in the case of Shopify orders, directly to the patient address entered by Practice in the Portal. Viome may update available SKUs, packaging, and lead times from time to time with reasonable notice to Practice.
5. TERMS OF PURCHASE
This Agreement governs the purchase and use of Viome Pro Solutions, and other available Viome tests as indicated in each Order Form or as ordered via Practice's Shopify account.
Ordering Methods: Tests may be ordered via the Viome Provider Portal or by contacting the Viome Account Representative.
Mixed Ordering (Order Form + Shopify):
Practice will place orders for in office tests AND Shopify single-order fulfillment (Drop Ship).
Order Form Purchases:
Shopify Purchases:
6. PRICING AND PAYMENTS
All Tests supplied under this Agreement are private pay only. Practice will not bill the Tests to any third-party payor. Practice acknowledges and agrees that the sale from Viome to Practice is a wholesale transaction for Practice's use with its patients.
7. PRICING AND BILLING TO PATIENTS
In the event that Practice chooses to bill patients directly for any services provided hereunder or any additional or related services (“Services”), Practice acknowledges and agrees that:
(a) Viome does not recommend, suggest, or endorse any particular pricing structure, markup, or billing methodology for Tests ordered through this Agreement;
(b) Practice is solely responsible for establishing its own pricing policies and charges to patients for Services, including any markup or administrative fees;
(c) Practice represents and warrants that it is familiar with and will comply with all applicable federal, state, and local laws, regulations, and professional ethics standards governing the billing and pricing of laboratory testing services, including but not limited to any anti-markup laws, direct billing requirements, and disclosure obligations that may apply in its jurisdiction;
(d) Practice acknowledges that certain states have enacted laws that regulate or restrict the ability of healthcare providers to mark up the cost of laboratory services, and that such laws may apply regardless of the patient's payment source (including self-pay patients);
(e) Practice agrees to seek independent legal counsel regarding its billing practices and compliance obligations under applicable law; and
(f) Practice shall indemnify and hold harmless Viome from any claims, liabilities, penalties, or damages arising from Practice's billing practices, pricing decisions, or failure to comply with applicable laws and regulations governing the same.
8. COMPLIANCE
Practice represents and warrants it is, and will remain, solely responsible for compliance with all federal, state, and local laws and regulations governing ordering, collection, marketing, pricing, sale, and use of the Tests in each jurisdiction where it offers them, including direct-access testing rules, test-ordering requirements, scope-of-practice rules, required patient consents/disclosures, advertising restrictions, and any reimbursement-related limits. Requirements vary by state and may change; Practice must monitor and ensure ongoing compliance. Viome makes no representation regarding state-by-state permissibility and disclaims responsibility for reimbursement or pricing decisions.
9. PRACTICE PORTAL AND MOBILE APP
10. INTELLECTUAL PROPERTY AND PROPRIETARY INFORMATION
11. NON-DISCLOSURE
"Confidential Information" as used herein means all information of Viome that is not generally known to the public, whether of a technical, business or other nature (including, without limitation, intellectual property, trade secrets, know-how and information relating to products, product packaging, technology, customers, vendors, distributors, pricing, business plans, promotional and marketing activities, finances and other business affairs), that is disclosed by Viome to the Practice under this Agreement and that is either identified as confidential, or that Practice would reasonably know is confidential based on the nature of the information or the circumstances of its disclosure. Practice agrees during the Term of this Agreement and 2 years after the Term has ended not to disclose, share, or otherwise make available any Viome Confidential Information to third parties without prior written consent from Viome.
12. RESTRICTIONS AND PROHIBITED ACTIVITIES
4. Expirations: Based on the reagents used to process test samples, kits expire on the dates printed on the kit sleeves. Practices agree to use the kits before their expiration dates.
13. HIPAA AND PHI COMPLIANCE
14. REPRESENTATIONS, WARRANTIES, AND DISCLAIMERS
15. LIMITATION OF LIABILITY
IN NO EVENT WILL EITHER PARTY BE LIABLE FOR ANY SPECIAL, INCIDENTAL, PUNITIVE OR CONSEQUENTIAL DAMAGES OR FOR ANY LOST PROFITS OR REVENUE, OR FOR THE COSTS OF PROCURING SUBSTITUTE PRODUCTS, ARISING OUT OF, RELATING TO OR IN CONNECTION WITH THIS AGREEMENT, WHETHER SUCH LIABILITY ARISES FROM ANY CLAIM BASED UPON CONTRACT, WARRANTY, TORT (INCLUDING NEGLIGENCE), PRODUCT LIABILITY OR OTHERWISE, WHETHER OR NOT A PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH LOSS OR DAMAGE.
16. INDEMNIFICATION
17. DISPUTE RESOLUTION AND GOVERNING LAW
18. TERMINATION
19. GENERAL PROVISIONS
20. LEGAL AUTHORITY
By clicking the "Agree & Continue" button, checking any acceptance box, accessing the Provider Portal, ordering Tests, or otherwise using the Services after being presented with this Agreement, Practice represents and warrants that the individual accepting this Agreement has authority to bind the Practice and that Practice shall be responsible for any acceptance made using credentials issued to its personnel or representatives.
VIOME LIFE SCIENCES, INC.
By:
Name: Naveen Jain
Title: CEO
PRACTICE
By:
Name:
Title:
Products & Service Addendum
Current as of June 20, 2026
This Viome Pro Solutions Products and Services Addendum to the Diagnostic Test Purchase Agreement (“Addendum”) contains a list of Viome’s most current Viome Pro Solutions Products and Service. This Addendum may be revised and updated by Viome from time to time in its sole discretion. Any revisions or updates will be effective as of the date stated at the top of this Addendum.
Precision Health Pro™ (“PH Pro Test”)
Please read the applicable product descriptions on Viome Pro website for further details: https://www.viomepro.com/
Oral Health Pro™ (“OH Pro Test”)
Please read the applicable product descriptions on Viome Pro website for further details: https://www.viomepro.com/
Gut Health Pro™ ("GH Pro Test")
Please read the applicable product descriptions on Viome Pro website for further details: https://www.viomepro.com/
Add Ons
CancerDetect Add On
Please see the applicable product and service descriptions for further details at Viome Pro website: https://www.viomepro.com/ and on CancerDetect website: https://cancerdetect.viome.com/
Business Associate Agreement
This Business Associate Agreement (“BAA”) is made and entered into as of Effective Date (specified below) by and between the Provider/Practice Name, a Covered Entity (“Covered Entity” or “CE”) and Viome Life Sciences, Inc., a Business Associate (“Business Associate” or “BA”) (each a “Party” and collectively the “Parties”).
WHEREAS, CE and BA have entered into a binding Agreement (“Agreement”) under which Viome will provide for the CE’s use and evaluation of Viome Tests the details of which is specified in that Agreement signed/to be signed between the parties containing the applicable terms. The parties agree that BA will provide certain services to the CE pursuant to and for the purpose of that Agreement (“Services”); and
WHEREAS, in providing Services pursuant to the Agreement, BA will have access to Protected Health Information (“PHI”) (as defined below); and
WHEREAS, the Services provided by BA to CE’s HIPAA covered functions cause BA to be considered a “business associate” under the privacy, security, and breach notification regulations issued under the Health Insurance Portability and Accountability Act of 1996, Public Law 104-191 (“HIPAA”), and the Health Information Technology for Economic and Clinical Health Act, Public Law 111-5, as set forth in 45 C.F.R. Parts 160 and 164 (the Privacy Rule, Security Rule, Breach Notification Rule, and State Privacy and Security Requirements all as defined below are collectively referred to hereinafter as the “HIPAA Requirements”); and
WHEREAS, under this BAA, for the purpose of the Agreement, CE and BA wish to agree to certain provisions required by the HIPAA Requirements.
NOW, THEREFORE, in consideration of the mutual covenants and conditions contained herein and the continued provision of PHI by CE to BA under the Agreement in reliance on this BAA, the Parties agree as follows:
1. Definitions. For purposes of this BAA, the terms used throughout this BAA shall have the meanings given to them in Exhibit A.
2. Use and Disclosure of PHI.
(a) Except as otherwise provided in this BAA, BA may use or disclose PHI as reasonably necessary to provide the Services described in the Agreement to, or on behalf of, the CE, and to undertake other activities of BA permitted or required of BA by this BAA or as required by law.
(b) Except as otherwise limited by this BAA, CE authorizes BA to use and disclose PHI in its possession for the proper management and administration of BA’s business and to carry out its legal responsibilities. BA may disclose PHI for such purposes, provided that (i) such disclosures are required by law; or (ii) BA obtains, in writing, prior to making any disclosure to a third party (a) reasonable assurances from such third party that the PHI will be held confidential as provided under this BAA and used or further disclosed only as required by law or for the purpose for which it was disclosed to such third party; and (b) an agreement from such third party to notify BA immediately of any breaches of the confidentiality of the PHI, to the extent it has knowledge of such breach.
(c) BA may De-Identify PHI and use the resulting data for any legal purpose.
(d) BA shall not use or disclose PHI in a manner other than as provided in this BAA, as permitted under the HIPAA Requirements, or as required by law. BA shall use or disclose only the minimum necessary amount of PHI, in accordance with Section 13405(b) the applicable HIPAA Requirements, or any implementing regulations adopted thereunder, for each use or disclosure of PHI hereunder.
(e) Except as permitted under paragraph (a-c) of this section, BA shall not use and/or disclose PHI in a manner that would violate the HIPAA Requirements if done by CE.
3. Safeguards Against Misuse of PHI. BA shall use appropriate safeguards and comply with the applicable provisions of the HIPAA Requirements, and in particular the Security Rule, with respect to Electronic PHI, to prevent the use or disclosure of PHI other than as provided by the Agreement or this BAA.
4. Reporting Impermissible Disclosures of PHI and Security Incidents. BA shall report to CE in writing any use or disclosure of PHI not provided for by this BAA of which it becomes aware; and BA agrees to report to CE any Security Incident affecting Electronic PHI of CE of which it becomes aware. BA agrees to report any such event without unreasonable delay, but in no event later than twenty (20) calendar days of becoming aware of the event.
5. Reporting Breaches of PHI. BA shall notify CE in writing without unreasonable delay after discovery of any Breach of Unsecured PHI in accordance with 45 C.F.R. §164.410, but in no case later than twenty (20) calendar days after discovery. BA shall provide information regarding such Breach (including, to the extent possible, identification of each individual whose Unsecured PHI has been or is reasonably believed by BA to have been accessed, acquired, used, or disclosed during the Breach). Thereafter, the information shall be timely supplemented with additional information as may be obtained by Business Associate.
6. Mitigation of Disclosures of PHI. BA shall take reasonable measures to mitigate, to the extent practicable, any harmful effect that is known to BA of any use or disclosure of PHI by BA or its agents or subcontractors in violation of the requirements of this BAA, or of any Security Incident.
7. Agreements with Agents or Subcontractors. In accordance with 45 C.F.R. §§ 164.502(e)(1)(ii) and 164.308(b)(2), BA shall ensure that any of its agents or subcontractors that have access to, or to which BA provides PHI, (a) agrees in writing to the same restrictions, conditions, and requirements concerning the uses and disclosures of PHI as apply to BA with respect to PHI and as contained herein; and (b) agrees in writing to comply with the applicable provisions of the HIPAA Requirements with respect to any Electronic PHI that it creates, receives, maintains, or transmits on behalf of BA or CE.
8. Access to PHI by Individuals.
(a) To the extent that BA maintains a Designated Record Set on behalf of the CE, BA agrees to furnish CE with copies of the PHI maintained by BA in such Designated Record Set to enable CE to provide access to the PHI under 45 C.F.R. §164.524, in the time and manner designated by CE.
(b) In the event any individual or personal representative requests access to the individual’s PHI directly from Business Associate, BA shall forward that request within five (5) calendar days to CE.
(c) Any disclosure of, or decision not to disclose, the PHI requested by an individual or a personal representative and compliance with the requirements applicable to an individual’s right to obtain access to PHI shall be the sole responsibility of CE.
9. Amendment of PHI.
(a) To the extent that BA maintains a Designated Record Set on behalf of the CE, BA shall make available for amendment and/or shall amend PHI or a Record about an individual in such Designated Record Set, as directed by CE in accordance with procedures established by 45 C.F.R. § 164.526. Any request by CE to amend such information shall be completed by BA within ten (10) calendar days of CE’s written request.
(b) In the event that any individual requests that BA amend such individual’s PHI or Record in a Designated Record Set, BA shall forward such request promptly to CE.
(c) Any amendment of, or decision not to amend, the PHI or Record as requested by an individual and compliance with the requirements applicable to an individual’s right to request an amendment of PHI shall be the sole responsibility of the CE.
10. Accounting of Disclosures.
(a) BA shall document any disclosures of PHI made by it, to the extent that CE would have an obligation to account for such disclosures under 45 C.F.R. § 164.528. BA also shall make available information related to such disclosures as would be required for CE to respond to a request for an accounting of disclosures in accordance with 45 C.F.R. § 164.528. At a minimum, BA shall furnish CE the following with respect to any covered disclosures by Business Associate: (i) the date of disclosure of PHI; (ii) the name of the entity or person who received PHI, and, if known, the address of such entity or person; (iii) a brief description of the PHI disclosed; and (iv) a brief statement of the purpose of the disclosure which includes the basis for such disclosure.
(b) BA hereby agrees to implement an appropriate recordkeeping system to enable it to comply with the requirements of this Section. BA agrees to retain such records for a minimum of six (6) years.
(c) BA shall furnish to CE information collected in accordance with this Section promptly, but in no event later than fifteen (15) calendar days after written request by the CE, to permit CE to make an accounting of disclosures as required by 45 C.F.R. § 164.528, or in the event that CE elects to provide an individual with a list of its business associates, BA will provide an accounting of its disclosures of PHI upon request of the individual, if and to the extent required under the HIPAA Requirements and any regulations adopted thereunder.
(d) In the event that an individual delivers the request for an accounting directly to Business Associate, BA shall forward such request promptly to CE, but no later than five (5) business days from receipt of the request.
(e) CE shall maintain sole responsibility for preparing and delivering any accounting requested and for complying with the requirements applicable to an individual’s right to obtain an accounting of disclosures of PHI.
11. Assumption of Covered Entity Obligations. Except as expressly provided herein or in a writing duly signed by authorized representatives of the Parties as an amendment to either the Agreement or this BAA, BA shall not assume any obligations of CE under the HIPAA Requirements. To the extent that BA is to carry out any of CE’s obligations under the HIPAA Requirements as expressly provided herein or through a written amendment, BA shall comply with the requirements of the HIPAA Requirements that apply to CE in the performance of such obligation.
12. Availability of Books and Records. BA shall make available its internal practices, books, and records relating to the use and disclosure of PHI, upon request, to the Secretary of HHS for purposes of determining CE’s or BA’s compliance with the HIPAA Requirements and this BAA. Notwithstanding the foregoing, prior to any such disclosure to the Secretary of HHS or any other federal or state agency, BA shall notify CE in writing of such request and shall furnish CE with copies of such request. CE and BA agree to work together in responding to any such request, including but not limited to engaging in an effort to obtain a confidentiality agreement, protective order, injunction, or court order, if necessary, to preserve any applicable privilege.
13. CE’s Obligations.
(a) CE shall not request BA to use or disclose PHI in any manner that would not be permissible under, or that would violate, the HIPAA Requirements if done by the CE.
(b) To the extent that such limitations, changes, or restrictions may affect BA’s ability to use or disclose PHI to provide Services, CE will notify BA of:
(i) any limitations on the use or disclosure of PHI contained in CE’s Notice of Privacy Practices.
(ii) any changes in, or revocation of, any authorization by an individual to use or disclose his or her PHI; and/or
(iii) any restrictions on the uses or disclosures of PHI that CE has agreed to or is required to comply with under 45 C.F.R. § 164.522.
(c) CE will provide BA with only the minimum necessary PHI for BA to provide the Services.
14. Term and Termination.
(a) This BAA shall become effective on the date first written above and shall continue in effect until all obligations of the Parties have been met under the Agreement and under this BAA. Notwithstanding the foregoing, upon the expiration or termination of the underlying Agreement for any reason, this BAA shall automatically terminate, and such termination shall have the same effective date as the Agreement’s termination or expiration.
(b) Either party may immediately terminate this BAA, the Agreement, and any other related Agreements, if feasible, if/when that party makes a determination that the other party has breached a material term of this BAA and the defaulting party has failed to cure that material breach, to the non-defaulting party’s reasonable satisfaction, within thirty (30) calendar days after written notice from the non-defaulting party.
(c) Upon termination of the Agreement or this BAA for any reason, all PHI maintained by BA shall be returned to CE or destroyed by BA. BA shall not retain any copies of such information. This provision shall apply to PHI in the possession of BA’s agents and subcontractors. Within sixty (60) calendar days after the effective termination date of this BAA, CE shall retrieve or otherwise receive the PHI to be returned under this BAA; otherwise, BA shall be entitled, in its sole discretion and without the requirement of written notice to CE, to destroy the PHI, unless return or destruction of such PHI is reasonably determined infeasible by BA as described below. If return or destruction of the PHI is deemed not feasible, BA shall furnish CE with notification, in writing, of the conditions that make return or destruction infeasible. Upon determination by BA that return, or destruction of the PHI is infeasible, BA will extend the protections of this BAA to such information for as long as BA retains such information and will limit further uses and disclosures to those purposes that make the return or destruction of the information not feasible. This Section 14(c) shall survive any termination of this BAA.
15. Effect of BAA. This BAA is a part of and subject to the terms of the Agreement, except that to the extent any terms of this BAA conflict with any term of the Agreement, the terms of this BAA shall govern. In the event of inconsistency between the provisions of this BAA and mandatory provisions of the HIPAA Requirements, as amended pursuant to the HITECH Act or otherwise, or their interpretation by any court or regulatory agency of competent authority and jurisdiction over either Party hereto, the HIPAA Requirements, as interpreted by such court or agency, shall control. Where the provisions of this BAA are different from those mandated in the HIPAA Requirements but are nonetheless permitted by such rules as interpreted by courts or agencies, the provisions of this BAA shall control.
16. Regulatory References. A reference in this BAA to a section in the HIPAA Requirements means the section as amended or added by law or regulation, and as further amended, from time to time.
17. Notices. All notices, requests and demands or other communications to be given hereunder to a Party shall be made via first class mail, registered or certified or express courier to such Party’s address given below, and/or via facsimile to the facsimile telephone numbers listed below:
If to Covered Entity (Practice/Provider), to:
Covered Entity
CE Contact
If to Business Associate (Viome), to:
Business Associate
BA Contact
18. Amendments; Waiver; Interpretation. This BAA may not be modified, nor shall any provision be waived or amended, except in writing duly signed by authorized representatives of the Parties. The Parties agree to take such action as is necessary to amend this BAA from time to time as may be necessary for compliance with the HIPAA Requirements. A waiver with respect to one event shall not be construed as continuing, or as a bar to or waiver of any right or remedy as to subsequent events. To the extent they are unclear, the terms of this BAA shall be construed to allow for compliance by CE and BA with the HIPAA Requirements.
19. HITECH Act Compliance. The Parties acknowledge that the HITECH Act includes provisions that require significant changes to the Privacy Rule and the Security Rule, as well as provisions regarding promulgation of the Breach Notification Rule. Each Party agrees to comply with the applicable provisions of the HITECH Act and any implementing regulations issued thereunder.
20. No Third-Party Beneficiaries. BA and CE do not intend to confer, nor does anything express or implied in this BAA confer, upon any person other than BA and CE, and their respective successors or assigns, any rights, remedies or obligations or liabilities whatsoever.
21. Independent Contractor. As it relates to this BAA and the Agreement, BA’s status shall be that of an independent contractor.
In Witness Whereof, this BAA is executed by the Parties as of the date first written above.
COVERED ENTITY BUSINESS ASSOCIATE
(PRACTICE/PROVIDER): (VIOME LIFE SCIENCES, INC.):
By: By:
Name: Name: Naveen Jain
Title: Title: CEO
Exhibit A
to the BAA
Definitions. For purposes of this BAA, the terms below shall have the following meanings given to them:
(a) Breach shall mean the acquisition, access, use, or disclosure of PHI in a manner not permitted under the HIPAA Requirements which compromises the security or privacy of the PHI, as defined in 45 C.F.R. §164.402.
(b) Breach Notification Rule shall mean that portion of the HIPAA Requirements set forth at 45 C.F.R. Part 160 and in Subparts A and D of 45 C.F.R. Part 164.
(c) Designated Record Set shall have the meaning as defined in 45 C.F.R. § 164.501.
(d) De-Identify shall mean to alter the PHI such that the resulting information meets the requirements described in 45 C.F.R. § 164.514(a) and (b).
(e) Effective Date shall mean the date first written above.
(f) Electronic PHI shall mean any PHI maintained in or transmitted by electronic media as defined in 45 C.F.R. § 160.103.
(g) Health Care Operations shall have the meaning given to that term at 45 C.F.R. § 164.501.
(h) HHS shall mean the U.S. Department of Health and Human Services.
(i) HITECH Act shall mean the Health Information Technology for Economic and Clinical Health Act, enacted as part of the American Recovery and Reinvestment Act of 2009, Public Law 111-5, and the applicable regulations, all as amended.
(j) Privacy Rule shall mean that portion of the HIPAA Requirements set forth in 45 C.F.R. Part 160 and in Subparts A and E of 45 C.F.R. Part 164.
(k) Protected Health Information or PHI shall have the meaning as defined in 45 C.F.R. § 160.103 and shall include personally identifiable information as defined by applicable state laws or regulations.
(l) Security Incident shall mean the attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations in an information system. This term shall not include trivial incidents that occur on a daily basis, such as scans, “pings,” or unsuccessful attempts to penetrate computer networks or servers maintained by Business Associate. The term shall be limited to such incidents involving PHI or information systems containing electronic PHI.
(m) Security Rule shall mean that portion of the HIPAA Requirements set forth in 45 C.F.R. Part 160 and in Subparts A and C of 45 C.F.R. Part 164.
(n) Services means the services provided by Business Associate, as specified in the Agreement.
(o) State Privacy and Security Requirements mean any applicable state or federal laws or regulations regulating, or pertaining to, personally identifiable information or sensitive personally identifiable information.
(p) Unsecured PHI shall mean PHI that has not been secured in accordance with standards promulgated by the Secretary of HHS in guidance issued by HHS or the Office of Civil Rights (“OCR”), and under the HIPAA Requirements including, but not limited to, under Section 13402(h)(2) of the HITECH Act.