44 HIPAA PRIVACY AND SECURITY STANDARDS General If a Health Benefit P rogram is not exempt from the requirements of the Privacy Standards and the Security Standards of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) , then this Section shall apply. The Plan also intends to comply with any applicable state laws relating to privacy and security. Privacy and Security Standards The Plan shall not disclose Protected Health Information (PHI) to any member of an Employer’s workforce unless each of the conditions set out in this Section are met. PHI shall have the same definition as set forth in the Privacy Standards but generally shall mean individually identifiable information about the past, present or future physical or mental health or condition of an individual, including information about trea tment or payment for treatment. PHI shall include “genetic information,” as defined in the Privacy Standards. “Electronic Protected Health Information” shall have the same definition as set out in the Security Standards, but generally shall mean Protected Health Information that is transmi tted by or maintained in electronic media. PHI disclosed to members of the Employer’s workforce shall be used or disclosed by the Employer only for purposes of Plan administrative functions. The Plan ’s administrative functions shall include all Plan treatment, payment functions and health care operations. The terms “treatment,” “payment” and “health care operations” shall have the same definitions as set out in the Privacy Standards, but the term “pa yment” shall include activities taken to determine or fulfill Plan responsibilities with respect to eligibility, coverage, provision of benefits, or reimbursement for health care. Genetic information shall not be used or disclosed for “underwriting” purpos es, as defined in the Privacy Standards. The Plan shall disclose PHI only to members of the Employer’s workforce who are authorized to receive such PHI , and only to the extent and in the minimum amount necessary for that person to perform their duties with respect to the Plan . “Members of the Employer’s workforce” shall refer to all employees and other persons under the control of the Employer. The Employer shall keep an updated list of those authorized to receive PHI . 1) An authorized member of the Employer’s workforce who receives Protected Health Information shall use or disclose the Protected Health Information only to the extent necessary to perform their duties with respect to the Plan . 2) In the event that any member of the Employer’s workforce uses or discloses Protected Health Information other than as permitted by this Section and the Privacy Standards, the incident shall be reported to the Plan ’s Privacy Officer. The Privacy O fficer shall take appropriate action, including: a) investigation of the incident to determine whether the breach occurred inadvertently, through negligence or deliberately , whether there is a pattern of breaches , and the degree of harm caused by the breach;

2026 Benefits Guide by Snellings Walters - Page 92 2026 Benefits Guide by Snellings Walters Page 91 Page 93