OAR 125-055-0125
Methods of Compliance


In addition to referencing compliance with this Rule in a Contract with a Business Associate, Agency may comply with this Rule in any of the following ways:

(1)

Memorandum of Understanding. If a Business Associate is a government entity, the parties may comply with the requirements of this Rule by entering into a memorandum of understanding that accomplishes the objectives of this Rule and meets the Business Associate requirements of the Privacy Rule and the Security Rule.

(2)

Amendment. Agency may comply with the requirements of this Rule by executing an amendment or rider that amends Agency’s Contract and that contains the contract provisions required by this Rule.

(3)

Required by Law. If a Business Associate is Required by Law to perform a function or activity on behalf of an Agency or to provide a service described in the definition of Business Associate to an Agency, such Agency may disclose Protected Health Information to the Business Associate to the extent necessary to comply with the legal mandate without meeting the requirements of this Rule, provided that the Agency attempts in good faith to obtain satisfactory assurances required by OAR 125-055-0115 (Business Associate Contract Provisions), and, if such attempt fails, documents the attempt and the reasons that such assurances cannot be obtained.

Source: Rule 125-055-0125 — Methods of Compliance, https://secure.­sos.­state.­or.­us/oard/view.­action?ruleNumber=125-055-0125.

Last Updated

Jun. 8, 2021

Rule 125-055-0125’s source at or​.us