Technical Assistance for Mississippi Breast and Cervical Cancer Program(MS-BCCP)

Location: Mississippi
Posted: Aug 24, 2026
Due: Sep 25, 2026
Agency: State Government of Mississippi
Type of Government: State & Local
Category:
  • R - Professional, Administrative and Management Support Services
Solicitation No: 1301-27-R-IFBD-00004
Publication URL: To access bid details, please log in.

Procurement Details

Smart Number 1301-27-R-IFBD-00004 Advertised Date 08/24/2026 10:12 AM
RFx # 3160008227 Submission Date 09/25/2026 2:00 PM
RFx Status Open Major Procurement Category PERSONNEL SERVICES NON-IT
RFx Opening Date 09/25/2026 2:00 PM Sub Procurement Category PERSONNEL SERVICE - NON-TECHNOLOGY
RFx Type Invitation for Bid
Agency MS DEPT OF HEALTH
RFx Description The Mississippi State Department of Health (hereinafter MSDH or Agency) has issued this solicitation for the purpose of soliciting sealed bids from qualified Bidders to provide technical assistance for Mississippi Breast and Cervical Cancer Program MS

Contact Information
Name Patricia Youngblood Email PATRICIA.YOUNGBLOOD@MSDH.MS.GOV
Phone 6013593499 Fax

RFx Items
PRODUCT CATEGORY PRODUCT DESCRIPTION
91832 Serv ConsultNotClass

Awarded
VENDOR NAME VENDOR NUMBER AWARD DATE AWARD AMOUNT FUNDING SOURCE

Bid Attachments
Attachments
Attachment A
Attachments
Attachment B
Attachments
RFx_BCCP

Attachment Preview

MISSISSIPPI STATE DEPARTMENT OF HEALTH
BUSINESS ASSOCIATE AGREEMENT
This Business Associate Agreement is entered into by and between the Mississippi State Department of
Health ("MSDH") the Covered Entity and
("Business Associate"), hereinafter referred to as the Parties, and modifies any other prior existing
agreement or contract for this purpose. In consideration of the mutual promises below and the exchange
of information pursuant to this Agreement and in order to comply with all legal requirements for the
protection of this information, the Parties therefore agree as follows:
I. RECITALS
a. MSDH is a state agency with a principal place of business at 570 East Woodrow Wilson,
Jackson, MS 39215
b. Business Associate is a corporation qualified to do business in Mississippi that will act to
perform business services for MSDH with a principal place of business at
.
c. This Business Associate Agreement ("Agreement") is entered into pursuant to the Health
Insurance Portability and Accountability Act ("HIPAA") of 1996, as amended by the Genetic
Information Nondiscrimination Act ("GINA") of 2008 and the Health Information Technology
for Economic and Clinical Health Act ("HITECH Act"), Title XIII of Division A,
and Title IV of Division B of the American Recovery and Reinvestment Act ("ARRA") of 2009,
and its implementing regulations, including, but not necessarily limited to, 45 C.F.R. Part 160, and
45 C.F.R. Part 164 Subparts A and C ("Security Rule"), and 45 C.F.R. Part 160 Subparts A and E
("Privacy Rule"). These statutes and regulations are hereinafter collectively referred to as HIPAA.
MSDH, as a covered entity, is required to enter into this Agreement to obtain satisfactory
assurances that Business Associate will comply with and appropriately safeguard all Protected
Health Information ("PHI") Used, Disclosed, created, or received by Business Associate on behalf
of MSDH. Certain provisions of HIPAA and its implementing regulations apply to Business
Associate in the same manner as they apply to MSDH, and such provisions must be incorporated
into this Agreement.
d. MSDH desires to engage Business Associate to perform certain functions for, or on behalf of,
MSDH involving the Disclosure of PHI by MSDH to Business Associate, or the creation or Use of
PHI by Business Associate on behalf of MSDH, and Business Associate desires to perform such
functions, as set forth in the Underlying Agreement(s) which involve the exchange of information,
and wholly incorporated herein.
II. DEFINITIONS
a. "Breach" shall mean the acquisition, access, Use or Disclosure of PHI in a manner not
permitted by the Privacy Rule which compromises the security or privacy of the PHI,
and subject to the exceptions set forth in 45 C.F.R. 164.402.
b. "Business Associate" shall mean ,
including all workforce members, representatives, agents, successors, heirs, and permitted
assigns.
M SDH BAA Page 1 of 14 Form 1063
Rev. February 2026

c. "Covered Entity" shall mean the Mississippi State Department of Health, an agency of the State
of Mississippi.
d. "Data Aggregation" shall have the same meaning as the term "Data aggregation" in 45 C.F.R.
164.501.
e. "Designated Record Set" shall have the same meaning as the term "Designated Record Set" in
45 C.F.R. 164.501.
f. "Disclosure" shall have the same meaning as the term "Disclosure" in 45 C.F.R. 160.103.
g. "MSDH" shall mean the Mississippi State Department of Health, an agency of the State of
Mississippi.
h. "Individual" shall have the same meaning as the term "Individual" in 45 C.F.R. 160.103 and
shall include a person who qualifies as a personal representative in accordance with 45
C.F.R. 164.502(g).
i. "Privacy Officer" shall mean the person designated by MSDH to oversee its implementation of
and compliance with HIPAA.
j. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health
Information at 45 C.F.R. Parts 160 and 164, Subparts A and E.
k. "Protected Health Information" or "PHI" shall have the same meaning as the term "Protected
health information" in 45 C.F.R. 160.103, limited to the information created or received by
Business Associate from or on behalf of MSDH.
l. "Qualified Service Organization" shall have the same meaning as defined in 42 CFR 2.11.
m. "Required by Law" shall have the same meaning as the term "Required by law" in 45 C.F.R.
164.103.
n. "Secretary" shall mean the Secretary of the Department of Health and Human Services or
his/her designee
o. "Security Incident" shall have the same meaning as the term "Security incident" in 45 C.F.R.
164.304.
p. "Security Rule" shall mean the Security Standards for the Protection of Electronic Protected
Health Information at 45 C.F.R. Parts 160 and 164, Subparts A and C.
q. "Standard" shall have the same meaning as the term "Standard" in 45 C.F.R. 160.103.
r. "Underlying Agreement" shall mean any applicable Memorandum of Understanding ("MOU"),
agreement, contract, or any other similar device, and any proposal or Request for Proposal
("RFP") related thereto and agreed upon between the Parties, entered into between MSDH and
Business Associate. Under this Business Associate Agreement, "Underlying Agreement" shall .
refer to the following:
M SDH BAA Page 2 of 14 Form 1063
Rev. February 2026

s. "Unsecured Protected Health Information" shall have the same meaning as the term
"Unsecured protected health information" in 45 C.F.R. 164.402.
t. "Use" shall have the same meaning as the term "Use" in 45 C.F.R. 160.103
u. "Violation" or "Violate" shall have the same meaning as the terms "Violation" or "Violate" in 45
C.F.R. 160.103.
All other terms not defined herein shall have the meanings assigned in HIPAA and its implementing
regulations.
III. OBLIGATIONS AND ACTIVITIES OF BUSINESS ASSOCIATE
a. Business Associate agrees to not Use or Disclose PHI other than as permitted or required by this
Agreement and the Underlying Agreement(s), or as Required by Law.
b. Business Associate agrees to utilize appropriate safeguards and comply, where applicable,
with the HIPAA Privacy and Security Rules, to prevent Use or Disclosure of the PHI other
than as permitted or provided for by this Agreement and shall: (i) implement administrative,
physical, and technical safeguards that reasonably and appropriately protect the
confidentiality, integrity, and availability of Protected Health Information and Electronic
Protected Health Information that Business Associate creates, receives, maintains, or transmits
on behalf of MSDH; (ii) ensure that any subcontractor to whom Business Associate provides
such information agrees to implement reasonable and appropriate safeguards to protect it; and
(iii) report to MSDH any Security Incident of which Business Associate becomes aware.
c. Business Associate shall implement and maintain a comprehensive written information
security program that:
- Is aligned with NIST SP 800-53 Rev. 5 Moderate baseline controls, including but not limited
to the Access Control (AC), Identification and Authentication (IA), Audit and Accountability
(AU), System and Communications Protection (SC), Risk Assessment (RA), and Incident
Response (IR) control families.
- Incorporates administrative, technical, and physical safeguards consistent with HIPAA, the
HITECH Act, and Zero Trust Architecture principles.
- Is reviewed at least annually and updated based on risk assessments, emerging threats, and
regulatory changes.
d. Business Associate shall implement and enforce the Principle of Least Privilege, ensuring
that workforce members, systems, applications, and automated processes are granted only the
minimum access necessary to perform authorized functions.
- Access rights shall be:
Approved through documented authorization procedures
o
Reviewed at least quarterly
o
Immediately revoked upon termination or role change
o
Technically enforced through centralized access control mechanisms.
o
e. Business Associate shall implement:
M SDH BAA Page 3 of 14 Form 1063
Rev. February 2026

- Role-Based Access Control (RBAC) to ensure access to PHI is provisioned
based on defined job roles and responsibilities.
- Attribute-Based Access Control (ABAC) or equivalent dynamic access controls
where appropriate, incorporating contextual attributes such as:
User Role
o
Device trust level
o
Geographic location
o
Time of access
o
Risk score or authentication strength
o
- Access decisions shall be centrally managed and logged.
f. Business Associate agrees to mitigate, to the extent practicable, any harmful effect that is known
to Business Associate of a Use or Disclosure of PHI by Business Associate in Violation of the
requirements of this Agreement and/or state or federal laws and regulations.
g. Breaches and Security Incidents. During the term of this Agreement, Business Associate
agrees to implement reasonable systems for the discovery and prompt reporting of any actual or
suspected Breach or Security Incident. Business Associate agrees to take the following steps:
Notice to MSDH. (1) To notify their MSDH Point-of-Contact, MSDH IT Security Officer and
MSDH Privacy Officer without unreasonable delay, and no later than five (5) days after
discovery, by telephone call and email or registered or certified mail upon the discovery of
an actual or suspected Breach of Unsecured PHI in electronic media or in any other media. (2)
To notify their MSDH Point-of-Contact, MSDH IT Security Officer and MSDH Privacy Officer
without unreasonable delay, and no later than five (5) days after discovery, by telephone
call and email or registered or certified mail of any actual or suspected Security Incident
affecting this Agreement, including but not limited to an actual or suspected Security Incident
that involves data provided to MSDH by the Social Security Administration. A Breach or
Security Incident shall be treated as discovered by Business Associate as of the first day on
which the Breach or Security Incident is known, or by exercising reasonable diligence would
have been known, to any person (other than the person committing the Breach or Security
Incident) who is a workforce member, officer, or other agent of Business Associate.
The notification shall include, to the extent possible and subsequently as the information becomes
available, a reasonably detailed description of the actual or suspected Breach or Security Incident,
the identification of all Individuals whose Unsecured PHI is reasonably believed by Business
Associate to have been affected by the Breach or Security Incident along with any other available
information that is required to be included in the notification to the Individual, HHS and/or the
media, all in accordance with the data breach notification requirements set forth in 42 U.S.C.
17932 and 45 C.F.R. Parts 160 and 164, Subparts A, D, and E, or any other applicable notification
requirements.
Upon discovery of an actual or suspected Breach or Security Incident, Business Associate shall
take:
- Prompt corrective action to mitigate any risks or damages involved with the Breach or
Security Incident and to protect the operating environment; and
- Any action pertaining to such unauthorized Disclosure required by applicable Federal
and State laws and regulations.
M SDH BAA Page 4 of 14 Form 1063
Rev. February 2026

Investigation. To immediately investigate any such actual or suspected Breach or Security
Incident upon discovery in order to determine if the actual or suspected Breach or Security
Incident is a Violation of any applicable federal or state laws or regulations, and to submit
updated information by email or registered or certified mail, as it becomes available, to the
MSDH IT Security Officer and MSDH Privacy Officer.
Complete Report. To provide a complete written report by email or registered or certified mail of
the investigation to the MSDH IT Security Officer and MSDH Privacy Officer within ten (10)
working days of the discovery of any actual or suspected Breach or Security Incident. The report
shall include:
- the identification of each Individual whose PHI was or is believed to have been
involved;
- a reasonably detailed description of the types of PHI involved; and
- a full, detailed corrective action plan, including information on measures that were
taken to halt and/or contain any suspected or actual Breach of security, intrusion or
unauthorized Use or Disclosure.
If MSDH requests information in addition to that provided in the written report, Business
Associate shall make reasonable efforts to provide MSDH with such information. If necessary, a
supplemental report may be utilized to submit revised or additional information after the
completed report is submitted.
Notification of Individuals. If the cause of an actual Breach of PHI is attributable to Business
Associate or its subcontractors, agents or vendors, Business Associate shall notify each Individual
of the Breach when notification is required under state or federal law and shall pay any costs of
such notifications, as well as any costs associated with the Breach. The notifications shall comply
with the requirements set forth in 42 U.S.C. 17932 and its implementing regulations. The
MSDH IT Security Officer and MSDH Privacy Officer shall approve the time, manner, and
content of any such notifications and their review and approval must be obtained before the
notifications are made.
Responsibility for Reporting of Breaches. If the cause of a Breach of PHI is attributable to
Business Associate or its agents, subcontractors, or vendors, and Business Associate is a covered
entity as defined under HIPAA and the HIPAA regulations, Business Associate is responsible for
all required reporting of the Breach as specified in 42 U.S.C. 17932 and its implementing
regulations, including notification to media outlets and to the Secretary of the U.S. Department of
Health and Human Services. If Business Associate has reason to believe that duplicate reporting
of the same Breach or Security Incident may occur because its subcontractors, agents or vendors
may report the Breach or Security Incident to MSDH in addition to Business Associate, Business
Associate shall notify MSDH, and MSDH and Business Associate may take appropriate action to
prevent duplicate reporting. The Breach reporting requirements of this paragraph are in addition to
the reporting requirements set forth above.
h. Business Associate agrees to ensure that any subcontractors that create, receive, maintain, or
transmit PHI on behalf of the Business Associate agree to the same restrictions and conditions
that apply to the Business Associate with respect to such information, all in accordance with 45
C.F.R. 164.308 and 164.502.
i. If Business Associate stores, processes, or transmits MSDH data in cloud environments:
M SDH BAA Page 5 of 14 Form 1063
Rev. February 2026

- Cloud providers must maintain SOC 2 Type II or FedRAMP Moderate (or higher)
accreditation.
- PHI must remain within the continental United States.
- Cloud administrative access will be restricted and logged.
j. Business Associate will be monitored by MSDH supply chain management systems and
scored in UpGuard. Vendor shall maintain the appropriate score, for the risk category
defined in the MSDH Vendor Risk Management Policy, which will be provided on request.
k. Business Associate agrees to ensure that any subcontractors that create, receive, maintain, or
transmit electronic PHI on behalf of Business Associate agree to comply with the applicable
requirements of the Security Rule and Privacy Rule by entering into a Business Associate
Agreement, in accordance with 45 C.F.R. 164.308, 164.314, 164.502, and 164.504, and
Business Associate shall provide MSDH with a copy of all such executed agreements between
Business Associate and Business Associate's subcontractors. Business Associate understands
that submission of their subcontractors' Business Associate Agreement(s) to MSDH does not
constitute MSDH approval of any kind, including of the utilization of such subcontractors or of
the adequacy of such agreements.
l. Business Associate agrees that nothing in this Agreement is meant to take the place of any
HIPAA-mandated reporting duties that apply directly to the Business Associate as a covered
entity under HIPAA and its implementing regulations.
m. Business Associate agrees to provide access, at the request of MSDH, and in the time and
manner designated by MSDH, to PHI in a Designated Record Set, to MSDH or, as directed by
MSDH, to an Individual in order to meet the requirements under 45 C.F.R. 164.524.
n. Business Associate agrees to document such Disclosures of PHI and information related to such
Disclosures as would be required for MSDH to respond to a request by an Individual for an
accounting of Disclosures of PHI in accordance with 45 C.F.R. 164.528. Business Associate
agrees to retain such documentation for at least six (6) years after the date of Disclosure; the
provisions of this Section shall survive termination of this Agreement for any reason.
o. Where applicable, Business Associate agrees to retain and securely store all data and documents
falling under this Agreement and the Underlying Agreement(s) in accordance with HIPAA, the
HITECH Act, and their implementing regulations.
p. Business Associate agrees to make any amendment(s) to PHI in a Designated Record Set that
MSDH directs or agrees to pursuant to 45 C.F.R. 164.526 at the request of MSDH or an
Individual, and in the time and manner designated by MSDH.
q. Business Associate agrees to provide to MSDH or an Individual, in a time and manner
designated by MSDH, information collected in accordance with Section (III) of this
Agreement, to permit MSDH to respond to a request by an Individual for an accounting of
Disclosures of PHI in accordance with 45 C.F.R. 164.528.
r. Business Associate agrees that it shall only Use or Disclose the minimum PHI necessary to
perform functions, activities, or services for, or on behalf of, MSDH as specified in the
Underlying Agreement(s). Business Associate agrees to comply with any guidance issued by the
Secretary on what constitutes "minimum necessary" for purposes of the Privacy Rule, and any
minimum necessary policies and procedures communicated to Business Associate by MSDH.
s. Routine transmission of PHI by fax is not recommended. If information must be faxed,
M SDH BAA Page 6 of 14 Form 1063
Rev. February 2026

Business Associate agrees PHI shall be limited to those recipients who have a need to gain
access to the information. The information to be faxed shall be limited to the "minimum
necessary" to accomplish the proposed function. A cover sheet must be utilized which includes
a required confidential statement prohibiting unlawful redisclosure. In the event a fax is
received by an unintended recipient, Business Associate should obtain the recipient's contact
information, attempt to identify the misdirected document, and then contact MSDH Privacy
Officer. Generally, Business Associate should instruct the recipient of the misdirected fax to
await further instructions from the Business Associate. Recipients should not be told to throw
away a misdirected fax. MSDH may instruct the recipient to return or destroy the document,
depending on the facts.
t. Business Associate agrees that to the extent that Business Associate carries out MSDH's
obligations under the Privacy Rule, Business Associate will comply with the requirements of the
Privacy Rule that apply to MSDH in the performance of such obligation.
u. Business Associate agrees to make internal practices, books, and records, including policies and
procedures and PHI, relating to the Use and Disclosure of PHI received from, or created or
received by Business Associate on behalf of, MSDH available to the Secretary for purposes of
determining MSDH's compliance with the Privacy Rule.
v. Business Associate agrees that nothing in this Agreement shall permit Business Associate to
access, store, share, maintain, transmit or Use or Disclose PHI in any form via any medium with
any third party, including Business Associate's subcontractors, beyond the boundaries and
jurisdiction of the United States without express written authorization from MSDH.
w. Business Associate agrees that all MSDH data will be encrypted using industry standard
algorithms.
- At rest, data will be encrypted using FIPS 140-2 or 140-3 validated
cryptographic modules with AES-256 or stronger algorithms.
- In transit, TLS 1.2 or higher is required for the transmission of all MSDH
data.
- Encryption keys shall be managed in accordance with NIST SP 800-57
Part 1 Rev. 5 and NIST SP 800-53 Rev. 5 (SC-12, SC-28), including
secure generation, storage, rotation, archival, and destruction.
Cryptographic keys shall be protected using FIPS 140-2 or FIPS 140-3
validated modules and, where feasible, shall be stored separately from
encrypted data.
x. Business Associate agrees to comply with the State of Mississippi ITS Enterprise Security
Policy, which will be provided by MSDH upon request.
y. Business Associate agrees to make an executive summary of its most recent information
security audit available to MSDH upon request by MSDH.
z. The provisions of the HITECH Act that apply to Business Associate and are required to be
incorporated by reference in a business associate agreement are hereby incorporated into this
Agreement, including, without limitation, 42 U.S.C. 17935(b), (c), (d) and(e), and
17936(a) and (b), and their implementing regulations.
M SDH BAA Page 7 of 14 Form 1063
Rev. February 2026

aa. 42 U.S.C. 17931(b) and 17934(c), and their implementing regulations, each apply to
Business Associate with respect to its status as a business associate to the extent set forth in
each such section.
bb. Business Associate shall be responsible for, and shall reimburse MSDH for costs and expenses
associated with steps reasonably implemented by MSDH to mitigate any Breach or other non-
permitted Use or Disclosure of PHI or medical, health or personal information protected by other
federal or state law, including, without limitation, the following: data analysis to determine
appropriate mitigation steps in the event of a Breach, including assistance from Business
Associate in the investigation of the Breach and, as needed, access to Business Associate's
systems and records for purposes of Breach data analysis; preparation and mailing of
notification(s) about the Breach to impacted Individuals, the media and regulators; costs
associated with proper handling of inquiries from Individuals and other entities about the Breach
(such as the establishment of toll-free numbers, maintenance of call centers for intake, preparation
of scripts, questions/answers, and other communicative information about the Breach); credit
monitoring and account monitoring services for impacted Individuals for a reasonable period
(which shall be no less than 12 months); other mitigation action steps required of MSDH by
federal or state regulators; and other reasonable mitigation steps required by MSDH.
cc. Business Associate shall not, without written authorization from MSDH, perform marketing or
fundraising on behalf of MSDH, or engage in the types of communications on behalf of MSDH
that are excepted from the definition of "marketing" established at 45 C.F.R. 164.501. If MSDH
requests and authorizes Business Associate to engage in these activities, Business Associate shall
comply with the applicable provisions of the HITECH Act and the HIPAA Rules.
dd. Business Associate shall not directly or indirectly receive remuneration in exchange for an
Individual's PHI unless it is pursuant to specific written authorization by the Individual or
subject to an exception established in the HIPAA Rules.
Without prior written approval from MSDH, Business Associate shall not publicly release
ee.
any report, article, paper, graph, chart, or other product created, in whole or in part, using
data provided or developed under this Agreement.
ff.
Business Associate agrees to utilize reasonable measures (including training) to ensure compliance
with the requirements of this Agreement by employees who assist in the performance of functions or
activities under this Agreement and Use or Disclose MSDH data, and to discipline such employees
who intentionally violate any provisions of this Agreement.
IV. PERMITTED USES AND DISCLOSURES BY BUSINESS ASSOCIATE
a. General Use and Disclosure Provisions:
i. If applicable, Covered Entity and Business Associate hereby agree that this Agreement
constitutes a Qualified Service Organization Agreement ("QSOA") as required by 42
C.F.R. Part 2. Accordingly, information obtained by Business Associate relating to
individuals who may have been diagnosed as needing, or who have received, substance use
disorder treatment services shall be maintained and used only for purposes intended under
this Agreement and in conformity with all applicable provisions of 42 USC 290dd-2 and
the underlying federal regulations 42 CFR Part 2.
ii. Business Associate may Use or Disclose PHI to perform functions, activities, or services for,
or on behalf of, MSDH as specified in the Underlying Agreement(s), provided that such
Use or Disclosure would not Violate what is Required by Law or the Privacy Rule if done by
MSDH, except for the specific Uses and Disclosures set forth below, for the purpose of
performing the Underlying Agreement(s).
M SDH BAA Page 8 of 14 Form 1063
Rev. February 2026

b. Specific Use and Disclosure Provisions:
i. Business Associate may Use PHI, if necessary, for the proper management and
administration of the Business Associate or to carry out the legal responsibilities of the
Business Associate under the Underlying Agreement(s) entered into between MSDH
and Business Associate.
ii. Business Associate may Disclose PHI for the proper management and administration of
the Business Associate or to carry out the legal responsibilities of the Business Associate,
provided that Disclosures are Required by Law and the person to whom the PHI was
Disclosed notifies the Business Associate of any instances of which it is aware in which
the confidentiality of the information has been breached.
iii. If Business Associate must Disclose PHI pursuant to law or legal process, Business
Associate shall notify MSDH by phone and in writing without unreasonable delay and at
least five (5) days in advance of any Disclosure so that MSDH may take appropriate
steps to address the Disclosure, if needed.
iv. In the event that Business Associate works for more than one covered entity,
Business Associate may Use and Disclose PHI for Data Aggregation purposes,
however, only in order to analyze data for permitted health care operations, and only
to the extent that such is permitted under the Privacy Rule.
v. Business Associate may Use and Disclose de-identified health information if (a) the
Use is communicated to MSDH and (b) the de-identified health information meets the
implementation specifications for de-identification under the Privacy Rule.
V. OBLIGATIONS OF MSDH
a. MSDH shall provide Business Associate with the Notice of Privacy Practices that MSDH
produces in accordance with 45 C.F.R. 164.520, as well as any changes to such Notice of
Privacy Practices, upon request.
b. MSDH shall notify Business Associate of any limitation(s) in its Notice of Privacy Practices to the
extent that such limitation may affect Business Associate's Use or Disclosure of PHI.
c. MSDH shall notify Business Associate of any changes in, or revocation of, permission by an
Individual to Use or Disclose PHI, to the extent that such changes may affect Business
Associate's Use or Disclosure of PHI.
d. MSDH shall notify Business Associate of any restriction to the Use or Disclosure of PHI that
MSDH has agreed to in accordance with 45 C.F.R. 164.522, to the extent that such restriction
may affect Business Associate's Use or Disclosure of PHI.
e. Permissible Requests by MSDH: MSDH shall not request Business Associate to Use or Disclose
PHI in any manner that would not be permissible under the Privacy Rule if done by MSDH,
except as provided for in Section (IV) of this Agreement.
M SDH BAA Page 9 of 14 Form 1063
Rev. February 2026

VI. TERM AND TERMINATION
a. Term. For any new Underlying Agreement(s) entered into between MSDH and Business Associate, the
effective date of this Agreement is the effective date of the Underlying Agreement(s) entered into
between MSDH and Business Associate. For any ongoing Underlying Agreement(s) entered into
between MSDH and Business Associate, the effective date of this Agreement is the date first herein
written. This Agreement shall terminate when all of the PHI provided by MSDH to Business Associate
or created or received by Business Associate on behalf of MSDH, is destroyed or returned to MSDH,
or, if it is infeasible to return or destroy PHI, protections are extended to such information in
accordance with the termination provisions in this Section. Termination of this Agreement shall
automatically terminate the Underlying Agreement(s).
b. Termination for Cause. Upon MSDH's knowledge of a material Violation by Business
Associate, MSDH shall, at its discretion, either:
i. provide an opportunity for Business Associate to cure or end the Violation within a time
specified by MSDH, after which MSDH may in its discretion terminate this Agreement
and the Underlying Agreement(s) if Business Associate does not cure or end the
Violation within the time specified by MSDH; or
ii. immediately terminate this Agreement and the associated Underlying Agreement(s) if
Business Associate has broken a material term of this Agreement and cure is not
possible.
c. Effect of Termination.
i. Upon termination of this Agreement and the Underlying Agreement(s) for any reason,
Business Associate shall return or destroy all PHI received from or created or received
by Business Associate on behalf of, MSDH in accordance with State and Federal
retention guidelines. This provision shall also apply to PHI that is in the possession of
subcontractors or agents of Business Associate. Business Associate shall retain no
copies of the PHI.
Upon expiration, non-renewal, or termination of the underlying Agreement for any
reason (including lapse due to funding, procurement delays, or failure to renew)
Business Associate's obligations under this BAA shall survive with respect to all
Protected Health Information ("PHI") created, received, maintained, or transmitted
on behalf of Covered Entity.
The obligations of Business Associate under this Agreement shall survive
termination of this Agreement and shall continue until all such PHI has been
destroyed or returned to MSDH, or, if it is infeasible to return or destroy PHI,
protections are extended to such information in accordance with the termination
provisions in this Section.
ii. In the event that Business Associate determines that returning or destroying the PHI is
infeasible, Business Associate shall provide to MSDH notification of the conditions
that make return or destruction infeasible. Upon notification in writing that return or
destruction of PHI is infeasible, Business Associate shall extend the protections of
this Agreement to such PHI and limit further Uses and Disclosures to those purposes
that make the return or destruction infeasible, for so long as Business Associate
maintains such PHI.
M SDH BAA Page 10 of 14 Form 1063
Rev. February 2026

This is the opportunity summary page. It provides an overview of this opportunity and a preview of the attached documentation.
Daily notification on new contract opportunities

With GovernmentContracts, you can:

  • Find more opportunities and win more business
  • Receive daily alerts for all new bid opportunities
  • Get contract opportunities matched to your business
ONE WEEK FREE TRIAL

See also

...Small Molecule Drug Discovery Suite is a comprehensive software suite designed for the ...

State Government of Mississippi

Bid Due: 10/13/2026

...will be available for inspection, measurement, and investigation. Bids may be submitted in-person, ...

Biloxi Housing Authority

Bid Due: 10/01/2026

* Disclaimer: Information regarding bids, requests for proposals (RFPs), or requests for qualifications (RFQs) is provided on this website only for convenience and does not constitute official public notice. Persons wishing to respond to or inquire about bids, RFPs, or RFQs should contact the appropriate government department.