This page is an unofficial LFoD record and is not legal advice. Verify the document against the official source before relying on it.

Governor and Executive Council Agenda item PDF - 2026-03-04 - 191 GC Agenda 062525.pdf

Lorl A. Weaver

Comrolssioner

Eilen M. Lapointe

Chief Executive Officer

STATE OF NEW HAMPSHIRE

DEPARTMENT OF HEALTH AND HUMAN SERVICES

NEW HAMPSHIRE HOSPITAL

36 CLINTON STREET, CONCORD, NH 03301

603-271-5300 1-800-852-3345 Ext. 5300

Fax: 603-271-5395 TDD Access: 1-800-735-2964

www.dhhs.nh.gov

a

May 30. 2025

Her Excellency, Governor Kelly A. Ayotte

and the Honorable Council

State House

Concord, New Hampshire 03301

REQUESTED ACTION

Authorize the Department of Health and Human Services, New Hampshire Hospital, toenter Into a Sole Source contract with Occupational Health Centers of the Southwest, P.A,

(VC#177829-R001), Addison, TX, in the amount of $260,000 for provision of occupational health

services for New Hampshire Hospital (NHH) with the option to renew for up to three (3) additional

years, effective upon Governor and Council approval through June 30,2026. 32% General Funds

68% Other Funds (Agency Income).

Funds are available in the following account for State Fiscal Year 2025 and are anticipatedto be available in Stale Fiscal Year 2026, upon the availability and continued appropriation of

funds in the future operating budget, with the authority to adjust budget line items within the pricelimitation and encumbrances between state fiscal years through the Budget Office. If needed and

justified.

05-95-94-940010-87500000 Health and Social Services, Health and Human Services

Department, Health and Human Services: New Hampshire Hospital, New Hampshire

Hospital, Acute Psychiatric Services

State

Fiscal

Year

Class / Account Class Title Job Number Total Amount

2025 102-500731 Contracts for

Program Services

94029200 $130,000

2026 102-500731 Contracts for

Program Services

94029200 $130,000

Total $260,OQO

EXPLANATION

This request Is Sole Source because It was not competitively bid. The Department

currently has another contract for laboratory, pathology, and occupational health services with

Concord Hospital; the Department and Concord Hospital have mutually agreed to amend that

Her Excellency, Governor Kelly A. Ayotte

and the Honorable Council

contract to remove occupational health services specifically for New Hampshire Hospital from the

scope of work. The Department is requesting to enter into a new agreement with this Contractor

to avoid a gap in occupational health screenings, an essential part of the pre-employment

process. It is critical to maintain continuity in these screenings to prevent further delays in hiring,

and the need to quickly engage a vendor who can restore and sustain this process efficiently is

both urgent and time sensitive. The inability to maintain sufficient levels of occupational health

screenings required to assess prospective employees' ability to serve at NHH will cause

significant delays in hiring, which has recently resulted in several candidates to revoke their

acceptance of an offer of employment at NHH. In order to continue to build the vital NHH

workforce and rely less on the utilization of costly agency staff, the Department identified the

Contractor as immediately willing and able to efficiently process staff occupational health

screenings for pre-employment as required.

The Contractor is uniquely qualified to provide these services due to their large footprint

in New Hampshire and have the bandwidth to handle our referrals at several locations throughout

the state, near and far from NHH. Given that employees travel from all parts of the state, we feel

this contractor is tsest suited to providing efficient and effective services. The contractor also

utilizes a communication platform that provides information back to the state almost immediately

which supports the goal of improving the efficiency of our per-employment process, allowing the

staff member to start working sooner.

The purpose of this request is to provide occupational health services for NHH to new

employees, transferred employees, employees returning to work after injury or major illness and

determining if employees are fit for duty. Vendor will conduct physical exams, OSHA Respirator

questionnaire. Respirator Fit Tests and other like procedures while complying with employee

health policies In accordance with OSHA, blood borne pathogen standards and the U.S. Public

Health guidelines and provide vaccinations.

The Department will monitor services by holding quarterly meetings with the Contractor

and tracking the tumaround time of services requested by the Department.

As referenced in Exhibit A of the attached agreement, the parties have the option to extend

the agreement for up three (3) additional years, contingent upon satisfactory delivery of services,

available funding, agreement of the parties and Governor and Council approval.

Should the Govemor and Council not authorize this request. New Hampshire Hospital will

continue to have issues with quickly on-boarding new staff, addressing concerns that may arise

through the scope of each staff member's employment and may fail out of line with federal

regulations.

Area served: New Hampshire Hospital.

In the event that the Other Funds become no longer available, additional General Funds

will not be requested to support this program.

Respectfully sut)mitted,

Lori A. Weaver

Commissioner

The Department of Health and Human Services' Mission is to join communities and families

in providing opportunities for citizens to achieve health and independence.

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

Subject: Staff Occupational Heatlh (SS-2025-NHH-06-STAFF-01)

FORM NUMBER P-37 (version 2/23/2023)

Notice: This agreement and all of its attachments shall become public upon submission to Governor and

Executive Council for approval. Any information that is private, confidential or proprietary must

be clearly identified to the agency and agreed to in writing prior to signing the contract.

AGREEMENT

The State of New Hampshire and the Contractor hereby mutually agree as follows:

GENERAL PROVISIONS

1.1 State Agency Name

New Hampshire Department of Health and Human Services

1.2 State Agency Address

129 Pleasant Street

Concord, NH 03301-3857

1.3 Contractor Name

Occupational Health Centers of the Southwest, P. A.

1.4 Contractor Address

5080 Spectrum Drive, Suite 1200, Addison, TX 75001

1.5 Contractor Phone

Number

866-944-6046

1.6 Account Unit and Class

TBD

1.7 Completion Date

6/30/2026

1.8 Price Limitation

$260,000

1.9 Contracting Officer for State Agency

Robert W. Moore, Director

1.10 State Agency Telephone Number

(603)271-9631

l.ll Contractor Signature

Sigind by:

1 UM &. feiUf; m 5/16/2025

1.12 Name and Title of Contractor Signatory

Robert G. ^ff^asurer & corp. Sec

1.13 State Agency SignatureOocuSlgn«d by:

1 Dale: 5/20/2025

1.14 Name and Title of State Agency Signatory

Ellen Lapoin'^-jef Executive officer

1.15 Approval by the N.H. Department of Administration, Division of Personnel (if applicable)

By: Director, On:

1.16 Approval by the Attorney General (Form, Substance and Execution) (if applicable)^ O^uSlgntdby:

By; On: 5/21/2025

74a734844M H90..."

1.17 Approval by the Governor and Executive Council (if applicable)

G&C Item number: G&C Meeting Date:

retary

Contractor Initial^

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

2. SERVICES TO BE PERFORMED. The State of New

Hampshire, acting through the agency identified in block 1.1

("State"), engages contractor identified in block 1.3 ("Contractor")

to perform, and the Contractor shall perform, the work or sale of

goods, or both, identified and more particularly described in the

attached EXHIBIT B which is incorporated herein by reference

("Services").

3. EFFECTIVE DATE/COMPLETION OF SERVICES.

3.1 Notwithstanding any provision of this Agreement to the

contrary, and subject to the approval of the Governor and

Executive Council of the State of New Hampshire, if applicable,

this Agreement, and all obligations of the parties hereunder, shall

become, effective on the date the Governor and Executive Council

approve this Agreement, unless no such approval is required, in

which case the Agreement shall become effective on the date the

Agreement is signed by the State Agency as shown in block 1.13

("Effective Date").

3.2 If the Contractor commences the Services prior to the Effective

Date, all Services performed by the Contractor prior to the

Effective Date shall be performed at the sole risk of the Contractor,

and in the event that this Agreement does not become effective, the

State shall have no liability to the Contractor, including without

limitation, any obligation to pay the Contractor for any costs

incurred or Services performed.

3.3 Contractor must complete all Services by the Completion Date

specified in block 1.7.

4. CONDITIONAL NATURE OF AGREEMENT.

Notwithstanding any provision of this Agreement to the contrary,

all obligations of the State hereunder, including, without limitation,

the continuance of payments hereunder, are contingent upon the

availability and continued appropriation of funds. In no event shall

the State be liable for any payments hereunder in excess of such

available appropriated funds. In the event of a reduction or

termination of appropriated funds by any state or federal legislative

or executive action that reduces, eliminates or otherwise modifies

the appropriation or availability of funding for this Agreement and

the Scope for Services provided in EXHIBIT B, in whole or in part,

the State shall have the right to withhold payment until such funds

become available, if ever, and shall have the right to reduce or

terminate the Services under this Agreement immediately upon

giving the Contractor notice of such reduction or termination. The

State shall not be required to transfer funds from any other account

or source to the Account identified in block 1.6 in the event funds

in that Account are reduced or unavailable.

5. CONTRACT PRICE/PRICE LIMITATION/ PAYMENT.

5.1 The contract price, method of payment, and terms of payment

are identified and more particularly described in EXHIBIT C

which is incorporated herein by reference.

5.2 Notwithstanding any provision in this Agreement to the

contrary, and notwithstanding unexpected circumstances, in no

event shall the total of all payments authorized, or actually made

hereunder, exceed the Price Limitation set forth in block 1.8. The

payment by the State of the contract price shall be the only and the

complete reimbursement to the Contractor for all expenses, of

whatever nature incurred by the Contractor in the perfonnance

hereof, and shall be the only and the complete compensation to the

Contractor for the Services.

5.3 The State reserves the right to offset from any amounts

otherwise payable to the Contractor under this Agreement those

liquidated amounts required or permitted by N.H. RSA 80:7

through RSA 80:7-c or any other provision of law.

5.4 The State's liability under this Agreement shall be limited to

monetary damages not to exceed the total fees paid. The Contractor

agrees that it has an adequate remedy at law for any breach of this

Agreement by the State and hereby waives any right to specific

performance or other equitable remedies against the State.

6. COMPLIANCE BY CONTRACTOR WITH LAWS AND

REGULATIONS/EQUAL EMPLOYMENT

OPPORTUNITY.

6.1 In connection with the performance of the Services, the

Contractor shall comply with all applicable statutes, laws,

regulations, and orders of federal, state, county or municipal

authorities which impose any obligation or duty..upon the

Contractor, including, but not limited to, ciyil rights and equal

employment opportunity laws and the Governor's order on Respect

and Civility in the Workplace, Executive order 2020-01. In

addition, if this Agreement is funded in any part by monies of the

United States, the Contractor shall comply with all federal

executive orders, rules, regulations and statutes, and with any rules,

regulations and guidelines as the State or the United States issue to

implement these regulations. The Contractor shall also comply

with all applicable intellectual property laws.

6.2 During the term of this Agreement, the Contractor shall not

discriminate against employees or applicants for employment

because of age, sex, sexual orientation, race, color, marital status,

physical or mental disability, religious creed, national origin,

gender identity, or gender expression, and will take affirmative

action to prevent such discrimination, unless exempt by state or

federal law. The Contractor shall ensure any subcontractors

comply with these nondiscrimination requirements.

6.3 No payments or transfers of value by Contractor or its

representatives in connection with this Agreement have or shall be

made which have the purpose or effect of public or commercial

bribery, or acceptance of or acquiescence in extortion, kickbacks,

or other unlawful or improper means of obtaining business.

6.4. The Contractor agrees to permit the State or United States

access to any of the Contractor's books, records and accounts for

the purpose of ascertaining compliance with this Agreement and

all rules, regulations and orders pertaining to the covenants, terms

and conditions of this Agreement.

7. PERSONNEL.

7.1 The Contractor shall at its own expense provide all personnel

necessary to perform the Services. The Contractor warrants that all

personnel engaged in the Services shall be qualified to perform the

Sers'ices, and shall be properly licensed and otherwise authorized

to do so under all applicable laws.

7.2 The Contracting Officer specified in block 1.9, or any

successor, shall be the State's point of contact pertaining to this

Agreement.

Contractor Initi

m

Date

1G/202S

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

8. EVENT OF DEFAULT/REMEDIES.

8.1 Any one or more of the following acts or omissions of the

Contractor shall constitute an event of default hereunder ("Event

of Default"):

8.1.1 failure to perform the Services satisfactorily or on schedule;

8.1.2 failure to submit any report required hereunder; and/or

8.1.3 failure to perform any other covenant, term or condition of

this Agreement.

8.2 Upon the occurrence of any Event of Default, the State may

take any one, or more, or all, of the following actions:

8.2.1 give the Contractor a written notice specifying the Event of

Default and requiring it to be remedied within, in the absence of a

greater or lesser specification of time, thirty (30) calendar days

from the date of the notice; and if the Event of Default is not timely

cured, terminate this Agreement, effective two (2) calendar days

after giving the Contractor notice of termination;

8.2.2 give the Contractor a written notice specifying the Event of

Default and suspending all payments to be made under this

Agreement and ordering that the portion of the contract price which

would otherwise accrue to the Contractor during the period from

the date of such notice until such time as the State determines that

the Contractor has cured the Event of Default shall never be paid

to the Contractor;

8.2.3 give the Contractor a written notice specifying the Event of

Default and set off against any other obligations the State may owe

to the Contractor any damages the State suffers by reason of any

Event of Default; and/or

8.2.4 give the Contractor a written notice specifying the Event of

Default, treat the Agreement as breached, terminate the Agreement

and pursue any of its remedies at law or in equity, or both.

9. TERMINATION.

9.1 Notwithstanding paragraph 8, the State may, at its sole

discretion, terminate the Agreement for any reason, in whole or in

part, by thirty (30) calendar days written notice to the Contractor

that the State is exercising its option to terminate the Agreement.

9.2 In the event of an early termination of this Agreement for any

reason other than the completion of the Services, the Contractor

shall, at the State's discretion, deliver to the Contracting Officer,

not later than fifteen (15) calendar days after the date of

termination, a report ("Termination Report") describing in detail

all Services performed, and the contract price earned, to and

including the date of termination. In addition, at the State's

discretion, the Contractor shall, within fifteen (15) calendar days

of notice of early termination, develop and submit to the State a

transition plan for Services under the Agreement.

10. PROPERTY OWNERSHIP/DISCLOSURE.

10.1 As used in this Agreement, the word "Property" shall mean

all data, information and things developed or obtained during the

performance of, or acquired or developed by reason of, this

Agreement, including, but not limited to, all studies, reports, files,

formulae, surveys, maps, charts, sound recordings, video

recordings, pictorial reproductions, drawings, analyses, graphic

representations, computer programs, computer printouts, notes,

letters, memoranda, papers, and documents, all whether finished or

unfinished.

10.2 All data and any Property which has been received from the

State, or purchased with funds provided for that purpose under this

Agreement, shall be the property of the State, and shall be returned

to the State upon demand or upon termination of this Agreement

for any reason.

10.3 Disclosure of data, information and other records shall be

governed by N.H. RSA chapter 91-A and/or other applicable law.

Disclosure requires prior written approval of the State.

11. CONTRACTOR'S RELATION TO THE STATE. In the

performance of this Agreement the Contractor is in all respects an

independent contractor, and is neither an agent nor an employee of

the State. Neither the Contractor nor any of its officers, employees,

agents or members shall have authority to bind the State or receive

any benefits, workers' compensation or other emoluments

provided by the State to its employees.

12. ASSIGNMENT/DELEGATION/SUBCONTRACTS.

12.1 Contractor shall provide the State written notice at least fifteen

(15) calendar days before any proposed assignment, delegation, or

other transfer of any interest in this Agreement. No such

assignment, delegation, or other transfer shall be effective without

the written consent of the State.

12.2 For purposes of paragraph 12, a Change of Control shall

constitute assignment. "Change of Control" means (a) merger,

consolidation, or a transaction or series of related transactions in

which a third party, together with its affiliates, becomes the direct

or indirect owner of fifty percent (50%) or more of the voting

shares or similar equity interests, or combined voting power of the

Contractor, or (b) the sale of all or substantially, all of the assets of

the Contractor.

12.3 None of the Services shall be subcontracted by the Contractor

without prior written notice and consent of the State.

12.4 The State is entitled to copies of all subcontracts and

assignment agreements and shall not be bound by any provisions

contained in a subcontract or an assignment agreement to which it

is not a party.

13. INDEMNIFICATION. The Contractor shall indemnify,

defend, and hold harmless the State, its officers, and employees

from and against all actions, claims, damages, demands,

judgments, fines, liabilities, losses, and other expenses, including,

without limitation, reasonable attorneys' fees, arising out of or

relating to this Agreement directly or indirectly arising from death,

personal injury, property damage, intellectual property

infringement, or other claims asserted against the State, its officers,

or employees caused by the acts or omissions of negligence,

reckless or willful misconduct, or fraud by the Contractor, its

employees, agents, or subcontractors. The State shall not be liable

for any costs incurred by the Contractor arising under this

paragraph 13. Notwithstanding the foregoing, nothing herein

contained shall be deemed to constitute a waiver of the State's

sovereign immunity, which immunity is hereby reserved to the

State. This covenant in paragraph 13 shall survive the termination

of this Agreement.

Contractor Initi,itiais

dI(q

C—Initial

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B.D71084984A62

14. INSURANCE.

14.! The Contractor shall, at its sole expense, obtain and

continuously maintain in force, and shall require any subcontractor

or assignee to obtain and maintain in force, the following

insurance:

14.1.1 commercial general liability insurance against all claims of

bodily injury, death or property damage, in amounts of not less than

$1,000,000 per occurrence and $2,000,000 aggregate or excess;

and

14.1.2 special cause of loss coverage form covering all Property

subject to subparagraph 10.2 herein, in an amount not less than

80% of the whole replacement value of the Property.

14.2 The policies described in subparagraph 14.1 herein shall be on

policy forms and endorsements approved for use in the State of

New Hampshire by the N.H. Department of Insurance, and issued

by insurers licensed in the Stale of New Hampshire.

14.3 The Contractor shall furnish to the Contracting Officer

identified in block 1.9, or any successor, a certificate(s) of

insurance for all insurance required under this Agreement. At the

request of the Contracting Officer, or any successor, the Contractor

shall provide certificate(s) of insurance for all renewal(s) of

insurance required under this Agreement. The certificate(s) of

insurance and any renewals thereof shall be attached and are

incorporated herein by reference.

15. WORKERS' COMPENSATION.

15.1 By signing this agreement, the Contractor agrees, certifies and

warrants that the Contractor is in compliance with or exempt from,

the requirements of N.H. RSA chapter 281-A ("Workers'

Compensation").

15.2 To the extent the Contractor is subject to the requirements of

N.H. RSA chapter 281-A, Contractor shall maintain, and require

any subcontractor or assignee to secure and maintain, payment of

Workers' Compensation in connection with activities which the

person proposes to undertake pursuant to this Agreement. The

Contractor shall flimish the Contracting Officer identified in block

1.9, or any successor, proof of Workers' Compensation in the

manner described in N.H. RSA chapter 281 -A and any applicable

renewals) thereof, which shall be attached and are incorporated

herein by reference. The State shall not be responsible for payment

of any Workers' Compensation premiums or for any other claim or

benefit for Contractor, or any subcontractor or employee of

Contractor, which might arise under applicable State of New

Hampshire Workers' Compensation laws in connection with the

performance of the Services under this Agreement.

18. AMENDMENT. This Agreement may be amended, waived or

discharged only by an instrument in writing signed by the parties

hereto and only afler approval of such amendment, waiver or

discharge by the Governor and Executive Council of the State of

New Hampshire unless no such approval is required under the

circumstances pursuant to State law, rule or policy.

19. CHOICE OF LAW AND FORUM.

19.1 This Agreement shall be governed, interpreted and construed

in accordance with the laws of the State of New Hampshire except

where the Federal supremacy clause requires otherwise. The

wording used in this Agreement is the wording chosen by the

parties to express their mutual intent, and no rule of construction

shall be applied against or in favor of any party.

19.2 Any actions arising out of this Agreement, including the

breach or alleged breach thereof, may not be submitted to binding

arbitration, but must, instead, be brought, and maintained in the

Merrimack County Superior Court of New Hampshire which shall

have exclusive jurisdiction thereof.

20. CONFLICTING TERMS. In the event of a conflict between

the terms of this P-37 form (as modified in EXHIBIT A) and any

other portion of this Agreement including any attachments thereto,

the terms of the P-37 (as modified in EXHIBIT A) shall control.

21. THIRD PARTIES. This Agreement is being entered into for

the sole benefit of the parties hereto, and nothing herein, express or

implied, is intended to or will confer any legal or equitable right,

benefit, or remedy of any nature upon any other person.

22. HEADINGS. The headings throughout the Agreement are for

reference purposes only, and the words contained therein shall in

no way be held to explain, modify, amplify or aid in the

interpretation, construction or meaning of the provisions of this

Agreement.

23. SPECIAL PROVISIONS. Additional or modifying

provisions set forth in the attached EXHIBIT A are incorporated

herein by reference.

24. FURTHER ASSURANCES. The Contractor, along with its

agents and affiliates, shall, at its own cost and expense, execute any

additional documents and take such further actions as may be

reasonably required to carry out the provisions of this Agreement

and give effect to the transactions contemplated hereby.

16. WAIVER OF BREACH. A Stale's failure to enforce its rights

with respect to any single or continuing breach of this Agreement

shall not act as a waiver of the right of the State to later enforce any

such rights or to enforce any other or any subsequent breach.

25. SEVERABILITV. In the event any of the provisions of this

Agreement are held by a court of competent jurisdiction to be

contrary to any state or federal law, the remaining provisions of

this Agreement will remain in full force and effect.

17. NOTICE. Any notice by a party hereto to the other party shall 26. ENTIRE AGREEMENT. Tjiis Agreement, which may be

be deemed to have been duly delivered or given at the time of executed in a number of counterparts, each of which shall be

mailing by certified mail, postage prepaid, in a United States Post deemed an original, constitutes the entire agreement and

Office addressed to the parties at the addresses given in blocks 1.2 understanding between the parties, and supersedes all prior

and 1.4, herein. agreements and understandings with respect to the subject matter

hereof.

Contractor Initials^

Dat#/16/2025

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT A

Revisions to Standard Agreement Provisions

1. Revisions to Form P-37, General Provisions

1.1. Paragraph 3, Effective Date/Completion of Services, is amended by deleting

subparagraph 3.3 in its entirety and replacing it as follows:

3.3. Contractor must complete all Services by the Completion Date specified

in block 1.7. The parties may extend the Agreement for up to three (3)

additional years from the Completion Date, contingent upon satisfactory

delivery of services, available funding, agreement of the parties, and

approval of the Governor and Executive Council.

1.2. Provision 10, Property Ownership/Disclosure, Section 10.3 are deleted and

replaced with the following:

10.3 Disclosure of data, information and other records shall be governed

by N.H. RSA chapter 91-A and/or other applicable law, and Exhibit D:

DHHS Information Security Requirements. Disclosure requires prior

written approval of the State.

1.3. Paragraph 12, Assignment/Delegation/Subcontracts, is amended by adding

subparagraph 12.5 as follows:

12.5. Subcontractors are subject to the same contractual conditions as the

Contractor and the Contractor is responsible to ensure subcontractor

compliance with those conditions. The Contractor shall have written

agreements with all subcontractors, specifying the work to be performed,

and if applicable, a Business Associate Agreement in accordance with

the Health Insurance Portability and Accountability Act. Written

agreements shall specify how corrective action shall be managed. The

Contractor shall manage the subcontractor's performance on an ongoing

basis and take corrective action as necessary. The Contractor shall

annually provide the State with a list of all subcontractors provided for

under this Agreement and notify the State of any inadequate

subcontractor performance.

mSS-2025-NHH-06-STAFF-01 Contractor Initials

5/16/2025

Occupational Health Centers of the Southwest, P.A. Date

Docusign Envelope ID: 16D4D899-A91F-4EB7-8998-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

Scope of Services

1. Statement of Work

1.1. The Contractor hereby enters.into an Agreement with the State of New

Hampshire, Department of Health and Human Services ("State" or

"Department"), to provide employee health services as requested by New

Hampshire Hospital (NHH) in order to ensure compliance with employee health

policies in accordance with Occupational Safety and Health Administration

(OSHA), blood bome pathogen standards, and U.S. Public Health Services

guidelines, including, but not limited to;

1.1.1. Screening employees for communicable and infectious diseases,

including, but not limited to:

1.1.1.1. Hepatitis B.

1.1.1.2. Measles.

1.1.1.3. Mumps.

1.1.1.4,Pertussis.

1.1.1.5. Rabies.

1.1.1.6. Rubella.

1.1.1.7. Tuberculosis.

1.1.1.8. Varicella.

1.1.1.9. Influenza.

1.1.1.10. COVID-19.

1.1.1.11. Tetanus.

1.1.1.12. Diphtheria.

1.1.2. Screening employees for occupational exposure to chemicals,

including, but not limited to, heavy metals and lead.

1.1.3. Referring employees showing any signs of potential added risk in the

performance of their job duties to their Primary Care Physician or

providing resources for the individual if the potential employee is

indigent and does not have a Primary Care Physician.

1.1.4. Conducting pre-placement and/or physical screenings, as

appropriate, within three (3) business days of referral, and

completing an OSHA Respirator Medical Evaluation Questionnaire,

prior to the pre-placement and/or physical, which includes:

1.1.4.1. Medical and occupational history reviews;

1.1.4.2. Respirator medical clearance exams; ^—mw*'

SS-2025-NHH-06-STAFF-01 Contraclor Initials

OccupaUonal Health Centers of the Southwest, P.A. Dat

Oocusign Envelope ID: 16O4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

1.1.4.3. Visual color discrimination exams;

1.1.4.4. Fit testing:

1.1.4.5. 9-panel urine drug test;

1.1.4.6. Physical capacity testing (if requested/needed);

1.1.4.7. Hearing examination (if requested/needed);

1.1.4.8. Medical clearance testing;

1.1.4.9. Spirometry testing (if requested/needed);

1.1.4.10. Providing immunization or screening in accordance with

OSHA blood borne pathogen standards and with the

Centers for Disease Control recommendations regarding

the Immunization of Health Care Workers;

1.1.4.11. Administering vaccinations for immunizations against

diseases, as requested by NHH, as listed in Section 1.1.1;

and

1.1.4.12. Providing chest radiographic services for employees who

present with a positive Tuberculin Skin Test or positive

QuantiFERON-TB Gold Test and annual screening for

employees with Latent Tuberculosis Infection.

1.2. The Contractor must attend quarterly meetings with NHH Infection Prevention.

1.3. Reporting and Online Data Transfers

1.3.1. The Contractor must provide, maintain and support a self-service

online health records management tool with account management

features that include search, export and copy authorization functions.

The Contractor must ensure the online tool provides access to:

1.3.1.1. Electronic creation of reports generated after each visit that

include:

1.3.1.1.1. Prospective applicant or employee name;

1.3.1.1.2. Demographics;

1.3.1.1.3. Date Seen;,

1.3.1.1.4. Type of referral;

1.3.1.1.5. Time of check-in;

1.3.1.1.6. Time of check-out;

1.3.1.1.7. Results, including test results;

1.3.1.1.8. Immunization updates;

1.3.1.1.9. Updates to prospective applicants |^^d

SS-2025-NHH-06-STAFF-01 Contractor Initials

5/16/2025

Occupatiorwi Health Centers of the Southwest. P.A. Date

Oocusign Envelope ID: 16D4D899-A91F-4EB7.899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

employee's non-injury and injury visit results,

including any potential work restrictions; and

1.3.1.1.10. Visit notes and remarks; and

1.3.1.2. Electronic creation and transmission of authorization and

associated forms made available to patients and the

Department.

1.3.2. The Contractor must maintain employee health records on all referrals

from NHH, including, but not limited to;

1.3.2.1. Verification of all services requested within three (3)

business days.

1.3.2.2. Result and/or findings of the above request, including any

declination forms.

1.3.3. The Contractor must make available a quarterly summary of all

Employee and Occupational Health Services to the NHH Human

Resource Coordinator II and to Administrator II at DHHS, Human

Resources, including, but not limited to:

1.3.3.1. Name of Employee.

1.3.3.2. Date of service.

1.3.3.3. Type of test including, but not limited to:

1.3.3.3.1. Pre-hire.

1.3.3.3.2. Physical capacity.

1.3.3.3.3. Immunization type.

1.3.3.3.4. Cost.

1.3.4. The Contractor may be required to provide other key data and

metrics to the Department in a format specified by the Department.

1.4. Data Location

1.4.1. The Contractor must provide its Services to the State and its end

users solely from data centers within the contiguous United States.

All storage, processing and transmission of Confidential Data and

State Data shall be restricted to information technology systems

within the contiguous United States. The Contractor must not allow

its End Users, as defined in Exhibit D. DHHS Information Security

Requirements, to store Confidential Data or State Data on portable

devices, including personal computers, unless prior written exception

is provided by the Department of Health and Human Service's

Information Security Office.

SS-2025-NHH-06-STAFF-01 Contractor Initials ^

5/16/2025

Occupational Health Centers of the Southwest, P.A. Date

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT 8

1.5. Data Protection

1.5.1. The Contractor must comply with Exhibit D, DHHS Information

Security Requirements.

1.6. Confidential Data

1.6.1. The Contractor must meet all information security and privacy

requirements as set by the Department and in accordance with the

Department's Information Security Requirements Exhibit as

referenced below.

1.6.2. The Contractor must use and disclose Protected Health Information

in compliance with the Standards for Privacy of Individually

Identifiable Health Information (Privacy Rule) (45 CFR Parts 160

and 164) under the Health Insurance Portability and Accountability

Act (HIPAA) of 1996, and in accordance with the attached Exhibit E,

Business Associate Agreement, which has been executed by the

parties.

1.7. Privacy Impact Assessment

1.7.1. Upon request, the Contractor must allow and assist the Department

in conducting a Privacy Impact Assessment (PIA) of its

system(s)/application(s)/web portal(s)/website(s) or Department

system(s)/application(s)/web portal(s)/website(s) hosted by the

Contractor, if Personally Identifiable Information (Pll) is collected,

used, accessed, shared, or stored. To conduct the PIA the Contractor

must provide the Department access to applicable systems and

documentation sufficient to allow the Department to assess, at

minimum, the following:

1.7.1.1. How Pll is gathered and stored;

1.7.1.2. Who will have access to Pll;

1.7.1.3. How Pll will be used in the system;

1.7.1.4. How individual consent will be achieved and revoked;

and

1.7.1.5. Privacy practices.

1.7.2. The Department may conduct follow-up PIAs in the event there are

either significant process changes or new technologies impacting the

collection, processing or storage of Pll.

1.8. Department Owned Devices, Systems and Network Usage

1.8.1. Contractor End Users, defined in the Department's Information

Security Requirements Exhibit that is incorporated into this

Agreement, authorized by the Department's Information ^cu^ity

1^

SS-2025-NHH-06-STAFF-01 Contractor Initials ^5/16/2025

OcojpaUonai Health Centers of the Southwest, P.A. Date ■.

Docusign Envelope ID: 16D4O899-A91F-4EB7-8998-O71084ge4A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

Office to use a Department issued device (e.g. computer, tablet,

mobile telephone) or access the Department network in the fulfilment

of this Agreement, each End User must:

1.8.1.1. Sign and abide by applicable Department and New

Hampshire Department of Information Technology (NH

DolT) use agreements, policies, standards, procedures

and guidelines, and complete applicable trainings as

required;

1.8.1.2. Use the information that they have permission to access

solely for conducting official Department business and

agree that all other use or access is strictly forbidden

including, but not limited, to personal or other private and

non-Department use, and that at no time shall they

access or attempt to access information without having

the express authority of the Department to do so;

1.8.1.3. Not access or attempt to access information in a manner

inconsistent with the approved policies, procedures,

and/or agreement relating to system entry/access;

1.8.1.4. Not copy, share, distribute, sub-license, modify, reverse

engineer, rent, or sell software licensed, developed, or

being evaluated by the Department, and at all times must

use utmost care to protect and keep such software strictly

confidential in accordance with the license or any other

agreement executed by the Department;

1.8.1.5. Only use equipment, software, or subscription(s)

authorized by the Department's Information Security

Office or designee;

1.8.1.6. Not install non-standard software on any Department

equipment unless authorized by the Department's

Information Security Office or designee;

1.8.1.7. Agree that email and other electronic communication

messages created, sent, and received on a Department-

issued email system are the property of the Department

of New Hampshire and to be used for business purposes

only. Email is defined as "internal email systems" or

"Department-funded email systems."

1.8.1.8. Agree that use of email must follow Department and NH

DolT policies, standards, and/or guidelines; and

1.8.1.9. Agree when utilizing the Department's email system:

—Inttisl

mSS-2025-NHH-06-STAFF-01 Contractor Initials

Occupational Health Centers of the Southwest, P.A. Date^^^^^^^^

Oocusign Envelope ID; 16D4D899-A91F-4EB7-e998-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

1.8.1.9.1. To only use a Department email address

assigned to them with a

affiliate.DHHS.NH.Gov".

1.8.1.9.2. Include in the signature lines information

identifying the End User as a non-Department

workforce member; and

1.8.1.9.3. Ensure the following confidentiality notice is

embedded underneath the signature line:

CONFIDENTIALITY NOTICE: "This message may

contain information that is privileged and confidential

and is intended only for the use of the individual(s)

to whom it is addressed. If you receive this message

in error, please notify the sender immediately and

delete this electronic message and any attachments

from your system. Thank you for your cooperation."

1.8.1.10. Contractor End Users with a Department issued email,

access or potential access to Confidential Data, and/or a

workspace in a Department building/facility, must:

1.8.1.10.1. Complete the Department's Annual

Information Security & Compliance

Awareness Training prior to accessing,

viewing, handling, hearing, or

transmitting Department Data or

Confidential Data.

1.8.1.10.2. Sign the Department's Business Use

and Confidentiality Agreement and

Asset Use Agreement, and the NH

DolT Department wide Computer Use

Agreement upon execution of the

Agreement and annually thereafter.

1.8.1.10.3. Only access the Department's intranet

to view.the Department's Policies and

Procedures and Information Security

webpages.

1.8.1.11. Contractor agrees, if any End User is found to be in

violation of any of the above terms and conditions, said

End User may face removal from the Agreement, and/or

criminal and/or civil prosecution, if the act constitutes a

violation of law.

— IntUal

m

SS-2025-NHH-06.STAFF-01 Contractor Initials.

5/16/2025

Occupational Health Centers of the Southwest. P.A. Date

Docusign Envelope ID: 16D4D899-A91F-4E87-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

1.8.1.12. Contractor agrees to notify the Department a minimum of

three business days prior to any upcoming transfers or

terminations of End Users who possess Department

credentials and/or badges or who have system privileges.

If End Users who possess Department credentials and/or

badges or who have system privileges resign or are

dismissed without advance notice, the Contractor agrees

to notify the Department's Information Security Office or

designee immediately.

1.9. Contract End-of-Life Transition Services

1.9.1. General Requirements

1.9.1.1. If applicable, upon termination or expiration of the

Agreement the parties agree to cooperate in good faith to

effectuate a smooth secure transition of the Services from

the Contractor to the Department and, if applicable, the

Contractor engaged by the Department to assume the

Services previously performed by the Contractor for this

section the new Contractor shall be known as

"Recipient"). Ninety (90) days prior to the end-of the

contract or unless otherwise specified by the Department,

the Contractor must begin working with the Department

and if applicable, the new Recipient to develop a Data

Transition Plan (DTP)- The Department shall provide the

DTP template to the Contractor.

1.9.1.2. The Contractor must use reasonable efforts to assist the

Recipient, in connection with the transition from the

performance of Services by the Contractor and its End

Users to the performance of such Services. This may

include assistance with the secure transfer of records

(electronic and hard copy), transition of historical data

(electronic and hard copy), the transition of any such

Service from the hardware, software, network and

telecommunications equipment and internet-related

information technology infrastructure ("Internal IT

Systems") of Contractor to the Internal IT Systems of the

Recipient and cooperation with and assistance to any

third-party consultants engaged by Recipient in

connection with the Transition Services.

1.9.1.3. If a system, database, hardware, software, and/or

software licenses (Tools) was purchased or created to

manage, track, and/or store Department Data in

relationship to this contract said Tools will be inv^ffled

SS-2025-NHH-06-STAFF-01 Contractor Initials

5/16/2025

Occupational Health Centers of the Southwest, PA. Date

Docusign Envelope ID; 16D4D899-A91F.-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

and returned to the Department, along with the inventory

document, once transition of Department Data is

complete.

1.9.1.4. The internal planning of the Transition Services by the

Contractor and its End Users shall be provided to the

Department and If applicable the Recipient in a timely

manner. Any such Transition Services shall be deemed

to be Services for purposes of this Agreement.

1.9.1.5. Should the data Transition extend beyond the end of the

Agreement, the Contractor agrees that the Information

Security Requirernents, and if applicable, the

Department's Business Associate Agreement terms and

conditions remain in effect until the Data Transition is

accepted as complete by the Department.

1.9.1.6. In the event where the Contractor has comingled

Department Data and the destruction or Transition of said

data is not feasible, the Department and Contractor will

jointly evaluate regulatory and professional standards for

retention requirements prior to destruction, refer to the

terms and conditions of the Department's DHHS

Information Security Requirements Exhibit.

2. Exhibits Incorporated

2.1. The Contractor must manage all confidential data related to this Agreement in

accordance with the terms of Exhibit D, DHHS Information Security

Requirements.

2.2. The Contractor must use and disclose Protected Health Information in

compliance with the Standards for Privacy of Individually Identifiable Health

Information (Privacy Rule) (45 CFR Parts 160 and 164) under the Health

Insurance Portability and Accountability Act (HIPAA) of 1996, and in

accordance with the attached Exhibit E, Business Associate Agreement, which

has been executed by the parties.

3. Additional Terms

3.1. Impacts Resulting from Court Orders or Legislative Changes

3.1.1. The Contractor agrees that, to the extent future state or federal

legislation or court orders may have an impact on the Services

described herein, the State has the right to modify Service priorities

and expenditure requirements under this Agreement so as to achieve

compliance therewith.

3.2. Federal Civil Rights Laws Compliance: Culturally and LingutstfCHlly

miSS-2025-NHH-06-STAFF-01 Contractor Initials V____

5/16/2025

Occupational Health Centers of the Southwest, P.A. Date

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT 8

Appropriate Programs and Services

3.2.1. The Contractor must submit:

3.2.1.1. A detailed description of the language assistance

services, within ten (10) days of the Effective Date of the

Agreement, to be provided to ensure meaningful access

to programs and/or services to individuals with limited

English proficiency: individuals who are deaf or have

hearing loss; individuals who are blind or have low

vision; and individuals who have speech challenges.

3.2.1.2. A written attestation, within 45 days of the Effective Date

of the Agreement and annually thereafter, that all

personnel involved the provision of services to

individuals under this Agreement have completed,

within the last 12 months, the Contractor Required

Training Video on Civil Rights-related Provisions in

DHHS Procurement Processes, which is accessible on

the Department's website

(https://www.dhhs.nh.gov/doing-business-dhhs/civil-

right-compliance-dhhs-vendors); and

3.2.1.3. The Department's Federal Civil Rights Compliance

Checklist within ten (10) days of the Effective Date of

the Agreement. The Federal Civil Rights Compliance

Checklist must have been completed within the last 12

months and is accessible on the Department's website

(https://www.dhhs.nh.gov/doing-business-dhhs/civil-

right-compliance-dhhs-vendors).

3.3. Credits and Copyright Ownership

3.3.1. All documents, notices, press releases, research reports and other

materials prepared during or resulting from the performance of the

services of the Agreement must include the following statement, "The

preparation of this (report, document etc.) was financed under an

Contract with the State of New Hampshire, Department of Health and

Human Services, with funds provided in part by the State of New

Hampshire and/or such other funding sources as were available or

required, e.g., the United States Department of Health and Human

Services."

3.3.2. All materials produced or purchased under the Agreement must have

prior approval from the Department before printing, production,

distribution or use.

3.3.3. The Department must retain copyright ownership for any ar],^,all

original materials produced, including, but not limited tofrepQrts,

SS-2025-NHH-06-STAFF-01 Conlractor Initials

5/16/2025

Occupational Health Centers of the Southwest. PA. Date

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D710S4984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT B

protocols, guidelines, brochures, posters, and resource directories.

3.3.4. The Contractor must not reproduce any materials produced under the

Agreement without prior written approval from the Department.

4. Records

4.1. The Contractor must keep records that include, but are not limited to:

4.1.1. Books, records, documents and other electronic or physical data

evidencing and reflecting all costs and other expenses incurred by the

Contractor in the performance of the Contract, and all income received

or collected by the Contractor.

4.1.2. All records must be maintained in accordance with accounting

procedures and practices, which sufficiently and properly reflect all such

costs and expenses, and which are acceptable to the Department, and

to include, without limitation, all ledgers, books, records, and original

evidence of costs such as purchase requisitions and orders, vouchers,

requisitions for materials, inventories, valuations of in-kind contributions,

labor time cards, payrolls, and other records requested or required by

the Department.

4.1.3. Statistical, enrollment, attendance or visit records for each recipient of

services, which records must include all records of application and

eligibility (including all forms required to determine eligibility for each

such recipient), records regarding the provision of services and all

invoices submitted to the Department to obtain payment for such

services.

4.1.4. Medical records on each patient/recipient of services.

4.2. During the term of this Agreement and the period for retention hereunder, the

Department, the United States Department of Health and Human Services, and

any of their designated representatives must have access to all reports and

records maintained pursuant to the Agreement for purposes of audit,

examination, excerpts and transcripts.

4.3. If, upon review of the Final Expenditure Report the Department must disallow

any expenses claimed by the Contractor as costs hereunder, the Department

retains the right, at its discretion, to deduct the amount of such expenses as

are disallowed or to recover such sums from the Contractor.

SS-2025-NHH-06-STAFF-01 ' Contraclor Initials,

5/16/2025

Occupational Health Centers of the Southwest, P.A. Date

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71O04984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT C

Payment Terms

1. This Agreement is funded by:

1.1. 32% General funds.

1.2. 68% Other funds (Provider Fees).

2. For the purposes of this Agreement the Department has identified:

2.1. The Contractor as a Contractor, In accordance with 2 CFR 200.331.

3. Payment shall be on fee-for-services basis for actual services provided in the

fulfillment of this Agreement, and shall be in accordance with the Exhibit C-1,

Fee Schedule.

4. The Contractor shall submit an invoice with supporting documentation to the

Department no later than the fifteenth (15th) working day of the month following

the month in which the services were provided. The Contractor shall ensure

each invoice:

4.1. Includes the Contractor's Vendor Number issued upon registering with

New Hampshire Department of Administrative Services.

4.2. Is submitted in a form that is provided by or otherwise acceptable to the

Department.

4.3. Identifies and requests payment for allowable costs incurred in the

previous month.

4.4. Includes supporting documentation of allowable costs with each invoice

that may include, but are not limited to, time sheets, payroll records,

receipts for purchases, and proof of expenditures, as applicable.

4.5. Is completed, dated and returned to the Department with the supporting

documentation for allowable expenses to initiate payment.

4.6. Is assigned an electronic signature, includes supporting documentation,

and is emailed or mailed to:

4.6.1. NH Hospital Invoices:

NHHFinancialServices(5?dhhs.nh.qov

Financial Manager

New Hampshire Hospital

121 So. Fruit St

Concord, NH 03301

5. The Department shall make payments to the Contractor within thirty (30) days

of receipt of each invoice and supporting documentation for authorized

expenses, subsequent to approval of the submitted invoice.

SS-2025-NHH-06-STAFF-01 Conlraclor Initials,

5/16/2025

Occupational Health Centers of the Southwest, P.A. Dale

Docusign Envelope ID; 16D4D89&-A91F-4E87-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT C

6. The final invoice and supporting documentation for authorized expenses shall

be due to the Department no later than forty (40) days after the contract

completion date specified in Form P-37, General Provisions Block 1.7

Completion Date.

7. Notwithstanding Paragraph 18 of the General Provisions Form P-37, changes

limited to adjusting amounts within the price limitation and adjusting

encumbrances between State Fiscal Years and budget class lines through the

Budget Office may be made by written agreement of both parties, without

obtaining approval of the Governor and Executive Council, if needed and

justified.

8. Audits

8.1.The Contractor must email an annual audit to dhhs.act@dhhs.nh.gov if

any of the following conditions exist:

8.1.1. Condition A - The Contractor expended $750,000 or more in

federal funds received as a subrecipient pursuant to 2 CFR Part

200, during the most recently completed fiscal year.

8.1.2. Condition B - The Contractor is subject to audit pursuant to the

requirements of NH RSA 7:28, lll-b.

8.1.3. Condition C - The Contractor is a public company and required

by the U.S. Securities and Exchange Commission (SEC)

regulations to submit an annual financial audit.

8.2. If Condition A exists, the Contractor shall submit an annual Single

Audit performed by an independent Certified Public Accountant (CPA)

to dhhs.act@dhhs;nh.gov within 120 days after the close of the

Contractor's fiscal year, conducted in accordance with the

requirements of 2 CFR Part 200, Subpart F of the Uniform

Administrative Requirements, Cost Principles, and Audit

Requirements for Federal awards.

8.2.1. The Contractor shall submit a copy of any Single Audit findings

and any associated corrective action plans. The Contractor

shall submit quarterly progress reports on the status of

implementation of the corrective action plan.

8.3. If Condition B or Condition C exists, the Contractor shall submit an

annual financial audit performed by an independent CPA within 120

days after the close of the Contractor's fiscal year.

8.4. Any Contractor that receives an amount equal to or greater than

$250,000 from the Department during a single fiscal year, regardless

of the funding source, may be required, at a minimum, to submit annual

financial audits performed by an independent CPA upon request.

SS-2025-NHH-06-STAFF-01 Contractor Initials

5/16/2025

Occopational Health Centers of the Southwest. P.A. Dale

Docusign Envelope 10:16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT C

8.5. In addition to, and not in any way in limitation of obligations of the

Agreement, it is understood and agreed by the Contractor that the

Contractor shall be held liable for any state or federal audit exceptions

and shall return to the Department all payments made under the

Agreement to which exception has been taken, or which have been

disallowed because of such an exception.

r—InttUIm

b55-^U^&-NMri-UD-5> I Al-I-Ul iioiKxa

5/16/2025

Occupational Health Centers of the Southwest, P.A. Date

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B.D71084984A62

New Hampshire Department of Health and Human Services

Staff Occupational Health

EXHIBIT C-1

Fee Schedule

Requested Service Cost Per Service

Standard Concerta-Level 1 Physical

Exam

$91

OSHA Respirator Questionnaire $55

Respirator Fit Test $64

MMR Vaccine $142

MMR liter 5259 Test $184

Tdap Vaccine $107

Varicella Vaccine $191

Varicella-Zoster IgG Antibody

4439SB Test

$115

QuantiFERON Gold Plus 36970 Test $169

Hep B Recombivax (3 shots) #1

Treatment

$123

Hepatitis B Surface Antibody Quant

8475 Treatment

$110

HPE Concentra-Level 2 Exam $92

Rapid eCup+/9 Panel - 3279 Test $95

Vision Color Ishihard 14 Plate Test $40

SS-2025-NHH-06-STAFF-01

Occupational Health Centers of the Southwest, P.A

r—InKljlm

v^uiiuauiui iiiuiais

5/16/2025

Date

Oocusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

A. Definitions

The following terms may be reflected and have the described meaning in this document:

1. "Breach" means the loss of control, compromise, unauthorized disclosure,

unauthorized acquisition, unauthorized access, or any similar term referring to

situations where persons other than authorized users and for an other than authorized

purpose have access or potential access to personally identifiable information,

whether physical or electronic. With regard to Protected Health Information," Breach"

shall have the same meaning as the term "Breach" in section 164.402 of Title 45,

Code of Federal Regulations.

2. "Computer Security Incident" shall have the same meaning "Computer Security

Incident" in section two (2) of NIST Publication 800-61, Computer Security Incident

Handling Guide, National Institute of Standards and Technology, U.S. Department of

Commerce.

3. "Confidential Information" or "Confidential Data" means all confidential information

disclosed by one party to the other such as all medical, health, financial, public

assistance benefits and personal information including without limitation, Substance

Abuse Treatment Records, Case Records, Protected Health Information and

Personally Identifiable Information.

Confidential Information also includes any and all information owned or managed by

the State of NH - created, received from or on behalf of the Department of Health and

Human Services (DHHS) or accessed in the course of performing contracted services

- of which collection, disclosure, protection, and disposition is governed by state or

federal law or regulation. This information includes, but is not limited to Protected

Health Information (PHI), Personal Information (PI), Personal Financial Information

(PFI), Federal Tax Information (FTI), Social Security Numbers (SSN), Payment Card

Industry (PCI), and or other sensitive and confidential information.

4. "End User" means any person or entity (e.g., contractor, contractor's employee,

business associate, subcontractor, other downstream user, etc.) that receives DHHS

data or derivative data in accordance with the terms of this Contract.

5. "HIPAA" means the Health Insurance Portability and Accountability Act of 1996 and

the regulations promulgated thereunder.

6. "Incident" means an act that potentially violates an explicit or implied security policy,

which includes attempts (either failed or successful) to gain unauthorized access to a

system or its data, unwanted disruption or denial of service, the unauthorized use of

a system for the processing or storage of data; and changes to system hardware,

firmware, or software characteristics without the owner's knowledge, instruction, or

consent. Incidents include the loss of data through theft or device misplacement, loss

mContractor Initials ^

V5. Last update 10/09/18. ^ 5/16/2025Page 1 of 9

Docusign Envelope ID: l6D4D899-A91F-4EB7-899B-p71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

or misplacement of hardcopy documents, and misrouting of physical or electronic

mail, all of which may have the potential to put the data at risk of unauthorized access,

use, disclosure, modification or destruction.

7. "Open Wireless Network" means any network or segment of a network that is not

designated by the State of New Hampshire's Department of Information Technology

or delegate as a protected network (designed, tested, and approved, by means of the

State, to transmit) will be considered an open network and not adequately secure for

the transmission of unencrypted PI, PFI, PHI or confidential DHHS data.

8. "Personal Information" (or "PI") means information which can be used to distinguish

or trace an Individual's identity, such as their name, social security number, personal

information as defined in New Hampshire RSA 359-C:19, biometric records, etc.,

alone, or when combined with other personal or identifying information which is linked

or linkable to a specific individual, such as date and place of birth, mother's maiden

name, etc.

9. "Privacy Rule" shall mean the Standards for Privacy of Individually Identifiable Health

Information at 45 C.F.R. Parts 160 and 164, promulgated under HIPAA by the United

States Department of Health and Human Services.

10. "Protected Health Information" (or "PHI") has the same meaning as provided in the

definition of "Protected Health Information" in the HIPAA Privacy Rule at 45 C.F.R. §

160.103.

11. "Security Rule" shall mean the Security Standards for the Protection of Electronic

Protected. Health Information at 45 C.F.R. Part 164, Subpart C, and amendments

thereto.

12. "Unsecured Protected Health Information" means Protected Health Information that is

not secured by a technology standard that renders Protected Health Information

unusable, unreadable, or indecipherable to unauthorized individuals and is developed

or endorsed by a standards developing organization that is accredited by the

American National Standards Institute.

RESPONSIBILITIES OF DHHS AND THE CONTRACTOR

A. Business Use and Disclosure of Confidential Information.

1. The Contractor must not use, disclose, maintain or transmit Confidential Information

except as reasonably necessary as outlined under this Contract. Further, Contractor,

including but not limited to all its directors, officers, employees and agents, must not

use, disclose, maintain or transmit PHI in any manner that would constitute a violation

of the Privacy and Security Rule.

Contractor Initials

V5. Last update 10/09/18

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

2. The Contractor must not disclose any Confidential Information in response to a request

for disclosure on the basis that it is required by law, in response to a subpoena, etc.,

without first notifying DHHS so that DHHS has an opportunity to consent or object to

the disclosure.

3. If DHHS notifies the Contractor that DHHS has agreed to be bound by additional

restrictions over and above those uses or disclosures or security safeguards of PHI

pursuant to the Privacy and Security Rule, the Contractor must be bound by such

additional restrictions and must not disclose PHI in violation of such additional

restrictions and must abide by any additional security safeguards.

4. The Contractor agrees that DHHS Data or derivative there from disclosed to an End

User must only be used pursuant to the terms of this Contract.

5. The Contractor agrees DHHS Data obtained under this Contract may not be used for

any other purposes that are not indicated in this Contract.

6. The Contractor agrees to grant access to the data to the authorized representatives of

DHHS for the purpose of inspecting to confirm compliance with the terms of this

Contract.

II. METHODS OF SECURE TRANSMISSION OF DATA

1. Application Encryption. If End User is transmitting DHHS data containing Confidential

Data between applications, the Contractor attests the applications have been evaluated

by an expert knowledgeable in cyber security and that said application's encryption

capabilities ensure secure transmission via the internet.

2. Computer Disks and Portable Storage Devices. End User may not use computer disks

or portable storage devices, such as a thumb drive, as a method of transmitting DHHS

data.

3. Encrypted Email. End User may only employ email to transmit Confidential Data if email

is encrypted and being sent to and being received by email addresses of persons

authorized to receive such information.

4. Encrypted Web Site. If End User is employing the Web to transmit Confidential Data, the

secure socket layers (SSL) must be used and the web site must be secure. SSL encrypts

data transmitted via a Web site.

5. File Hosting Services, also known as File Sharing Sites. End User may not use file hosting

services, such as Dropbox or Google Cloud Storage, to transmit Confidential Data.

6. Ground Mail Service. End User may only transmit Confidential Data via certified ground

mail within the continental U.S. and when sent to a named individual.

7. Laptops and PDA. If End User is employing portable devices to transmit Confidential Data

said devices must be encrypted and password-protected.

Contractor Initials

V5. Last update 10/09/18 nate 5/16/2025Page 3 of 9

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

8. Open Wireless Networks. End User may not transmit Confidential Data via an open

wireless network. End User must employ a virtual private network (VPN) when remotely

transmitting via an open wireless network.

9. Remote User Communication. If End User is employing remote communication to access

or transmit Confidential Data, a virtual private network (VPN) must be installed on the End

User's mobile device(s) or laptop from which information will be transmitted or accessed.

10. SSH File Transfer Protocol (SFTP), also known as Secure File Transfer Protocol. If End

User' is employing an SFTP to transmit Confidential Data, End User will structure the

Folder and access privileges to prevent inappropriate disclosure of information. SFTP

folders and sub-folders used for transmitting Confidential Data will be coded for 24-hour

auto-deletion cycle (i.e. Confidential Data will be deleted every 24 hours).

11. Wireless Devices. If End User is transmitting Confidential Data via wireless devices, all

data must be encrypted to prevent inappropriate disclosure of information.

RETENTION AND DISPOSITION OF IDENTIFIABLE RECORDS

The Contractor will only retain the data and any derivative of the data for the duration of this

Contract. After such time, the Contractor will have 30 days to destroy the data and any

derivative in whatever form it may exist, unless, otherwise required by law or permitted under

this Contract. To this end, the parties must:

A. Retention

1. The Contractor agrees it will not store, transfer or process data collected in

connection with the sen/ices rendered under this Contract outside of the United

States. This physical location requirement shall also apply in the implementation of

cloud computing, cloud service or cloud storage capabilities, and includes backup

data and Disaster Recovery locations.

2. The Contractor agrees to ensure proper security monitoring capabilities are in place

to detect potential security events that can impact State of NH systems and/or

Department confidential information for contractor provided systems.

3. The Contractor agrees to provide security awareness and education for its End

Users in support of protecting Department confidential information.

4. The Contractor agrees to retain all electronic and hard copies of Confidential Data

in a secure location and identified in section IV. A.2

5. The Contractor agrees Confidential Data stored in a Cloud must be in a

FedRAMP/HITECH compliant solution and comply with all applicable statutes and

regulations regarding the privacy and security. All servers and devices must have

currently-supported and hardened operating systems, the latest anti-viral,

antihacker, anti-spam, anti-spyware, and anti-malware utilities. The environment, as

a whole, must have aggressive intrusion-detection and firewall protection.

Contractor Initials

V5. Last update 10/09/18 5/16/2025

Oate

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

6. The Contractor agrees to and ensures its complete cooperation with the State's

Chief Information Officer in the detection of any security vulnerability of the hosting

infrastructure.

B. Disposition

1. If the Contractor will maintain any Confidential Information on its systems (or Its sub

contractor systems), the Contractor will maintain a documented process for securely

disposing of such data upon request or contract termination: and will obtain written

certification for any State of New Hampshire data destroyed by the Contractor or

any subcontractors as a part of ongoing, emergency, and or disaster recovery

operations. When no longer in use, electronic media containing State of New

Hampshire data shall be rendered unrecoverable via a secure wipe program in

accordance with industry-accepted standards for secure deletion and media

sanitization, or othenwise physically destroying the media (for example, degaussing)

as described in NISI Special Publication 800-88, Rev 1, Guidelines for Media

Sanitization, National Institute of Standards and Technology, U. S. Department of

Commerce. The Contractor will document and certify in writing at time of the data

destruction, and will provide written certification to the Department upon request.

The written certification will include all details necessary to demonstrate data has

been properly destroyed and validated. Where applicable, regulatory and

professional standards for retention requirements will be jointly evaluated by the

State and Contractor prior to destruction.

2. Unless otherwise specified, within thirty (30) days of the termination of this Contract,

Contractor agrees to destroy all hard copies of Confidential Data using a secure

method such as shredding.

3. Unless otherwise specified, within thirty (30) days of the termination of this Contract,

Contractor agrees to completely destroy all electronic Confidential Data by means

of data erasure, also known as secure data wiping.

IV. PROCEDURES FOR SECURITY

A. Contractor agrees to safeguard the DHHS Data received under this Contract, and any

derivative data or files, as follows;

1. The Contractor will maintain proper security controls to protect Department confidential

information collected, processed, managed, and/or stored in the delivery of contracted

services.

2. The Contractor will maintain policies and procedures to protect Department confidential

information throughout the information lifecycle, where applicable, (from creation,

transformation, use, storage and secure destruction) regardless of the media used to

store the data (i.e., tape, disk, paper, etc.).

Contractor Initials

1?^

V5. Last update 10/09/18 ^ 5/16/2025Page 5 of 9 Date

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

3. The Contractor will maintain appropriate authentication and access controls to

contractor systems that collect, transmit, or store Department confidential information

where applicable.

4. The Contractor will ensure proper security monitoring capabilities are in place to detect

potential security events that can impact State of NH systems and/or Department

confidential information for contractor provided systems.

5. The Contractor will provide regular security awareness and education for its End Users

in support of protecting Department confidential infonnation.

6. If the Contractor will be sub-contracting any core functions of the engagement

supporting the services for State of New Hampshire, the Contractor will maintain a

program of an internal process or processes that defines specific security expectations,

and monitoring compliance to security requirements that at a minimum match those for

the Contractor, including breach notification requirements.

7. The Contractor will work with the Department to sign and comply with all applicable

State of New Hampshire and Department system access and authorization policies and

procedures, systems access forms, and computer use agreements as part of obtaining

and maintaining access to any Department system(s). Agreements will be completed

and signed by the Contractor and any applicable sub-contractors prior to system access

being authorized.

8. If the Department determines the Contractor is a Business Associate pursuant to 45

CFR 160.103, the Contractor will execute a HIPAA Business Associate Agreement

(BAA) with the Department and is responsible for maintaining compliance with the

agreement.

9. The Contractor will work with the Department at its request to complete a System

Management Survey. The purpose of the survey is to enable the Department and

Contractor to monitor for any changes in risks, threats, and vulnerabilities that may

occur over the life of the Contractor engagement. The survey will be completed

annually, or an alternate time frame at the Departments discretion with agreement by

the Contractor, or the Department may request the survey be completed when the

scope of, the engagement between the Department and the Contractor changes.

10. The Contractor will not store, knowingly or unknowingly, any State of New Hampshire

or Department data offshore or outside the boundaries of the United States unless prior

express written consent is obtained from the Information Security Office leadership

member within the Department.

11. Data Security Breach Liability. In the event of any security breach Contractor shall make

efforts to investigate the causes of the breach, promptly take measures to prevent

Conlractor Initials

m

V5. Last update 10/09/18 ^ 5/16/2025Page 6 of 9 Date

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

future breach and minimize any damage or loss resulting from the breach. The State

shall recover from the Contractor all costs of response and recovery from

the breach, including but not limited to: credit monitoring services, mailing costs and

costs associated with website and telephone call center services necessary due to the

breach.

12. Contractor must, comply with all applicable statutes and regulations regarding the

privacy and security of Confidential Information, and must in all other respects maintain

the privacy and security of PI and PHI at a level and scope that is not less than the level

and scope of requirements applicable to federal agencies, including, but not limited to,

provisions of the Privacy Act of 1974 (5 U.S.C. § 552a), DHHS Privacy Act Regulations

(45 C.F.R. §5b), HIPAA Privacy and Security Rules (45 C.F'R. Parts 160 and 164) that

govern protections for individually identifiable health information and as applicable

under State law.

13. Contractor agrees to establish and maintain appropriate administrative, technical, and

physical safeguards to protect the confidentiality of the Confidential Data and to prevent

unauthorized use or access to it. The safeguards must provide a level and scope of

security that is not less than the level and scope of security requirements established

by the State of New Hampshire, Department of Information Technology. Refer to

Vendor Resources/Procurement at https://www.nh.gov/doit/vendor/index.htm for the

Department of Information Technology policies, guidelines, standards, and

procurement information relating to vendors.

14. Contractor agrees to maintain a documented breach notification and incident response

process. The Contractor will notify the State's Privacy Officer and the State's Security

Officer of any security breach immediately, at the email addresses provided in Section

VI. This includes a confidential information breach, computer security incident, or

suspected breach which affects or includes any State of New Hampshire systems that

connect to the State of New Hampshire network.

15. Contractor must restrict access to the Confidential Data obtained under this Contract

to only those authorized End Users who need such DHHS Data to perform their official

duties in connection with purposes identified in this Contract.

16. The Contractor must ensure that all End Users:

a. comply with such safeguards as referenced in Section IV A. above, implemented

to protect Confidential Information that is furnished by DHHS under this Contract

from loss, theft or inadvertent disclosure.

b. safeguard this information at all times.

c. ensure that laptops and other electronic devices/media containing PHI, PI, or

PFI are encrypted and password-protected.

Contractor Initials ^

V5. Last update 10/09/18

-

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

d. send emails containing Confidential Information only if encrypted and being sent

to and being received by email addresses of persons authorized to receive such

information.

e. limit disclosure of the Confidential Information to the extent permitted by law.

f. Confidential Information received under this Contract and individually identifiable

data derived from DHHS Data, must be stored in an area that is physically and

technologically secure from access by unauthorized persons during duty hours

as well as non-duty hours (e.g.. door locks, card keys, biometric identifiers, etc.).

g. only authorized End Users may transmit the Confidential Data, including any

derivative files containing personally identifiable information, and in all cases,

such data must be encrypted at all times when in transit, at rest, or when stored

on portable media as required In section IV above.

h. in all other instances Confidential Data must be.maintained, used and disclosed

using appropriate safeguards, as determined by a risk-based assessment of the

circumstances involved.

i. understand that their user credentials (user name and password) must not be

shared with anyone. End Users will keep their credential information secure.

This applies to credentials used to access the site directly or indirectly through a

third party application.

Contractor is responsible for oversight and compliance of their End Users. DHHS

reserves the right to conduct onsite inspections to monitor compliance with this Contract,

including the privacy and security requirements provided in herein. HIPAA, and other

applicable laws and Federal regulations until such time the Confidential Data is disposed

of in accordance with this Contract.

V. LOSS REPORTING

The Contractor must notify the State's Privacy Officer and Security Officer of any Security

Incidents and Breaches immediately, at the email addresses provided in Section VI.

The Contractor must further handle and report Incidents and Breaches involving PHI in

accordance with the agency's documented Incident Handling and Breach Notification

procedures and in accordance with 42 C.F.R. §§ 431.300 - 306. In addition to, and

notwithstanding, Contractor's compliance with all applicable obligations and procedures,

Contractor's procedures must also address how the Contractor will:

1. Identify Incidents;

2. Determine if personally identifiable information is involved in Incidents;

3. Report suspected or confirmed Incidents as required in this Exhibit or P-37;

C—lnitl«lm

V5. Lasl update 10/09/18 5/16/2025

Da'®

Docusign Envelope ID: 16D4D899-A91F-4EB7-8998-D71084984A62

New Hampshire Department of Health and Human Services

Exhibit D

DHHS Information Security Requirements

4. Identify and convene a core response group to determine the risk level of Incidents and

determine risk-based responses to Incidents; and

5. Determine whether Breach notification is required, and, if so, identify appropriate Breach

notification methods, timing, source, and contents from among different options, and

bear costs associated with the Breach notice as well as any mitigation measures.

Incidents and/or Breaches that implicate PI must be addressed and reported, as applicable,

in accordance with NH RSA 359-C:20.

VI. PERSONS TO CONTACT

A. DHHS Privacy Officer:

DHHSPrivacyOfficer@dhhs.nh.gov B.

DHHS Security Officer:

DHHSInformationSecurityOffice@dhhs.nh.gov

Contractor Initials

C—Inittal

V5. Last Update 10/09/18

Oocusign Envelope ID; 16D4O899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human

Exhibit E

BUSINESS ASSOCIATE AGREEMENT

The Contractor identified In Section 1.3 of the General Provisions of the Agreement (Form P-37)

("Agreement"), and any of its agents who receive use or have access to protected health

Information (PHI), as defined herein, shall be referred to as the "Business Associate." The State

of New Hampshire, Department of Health and Human Services, "Department" shall be referred

to as the "Covered Entity." The Contractor and the Department are collectively referred to as "the

parties."

The parties agree, to comply with the Health Insurance Portability and Accountability Act, Public

Law 104-191, the Standards for Privacy and Security of Individually Identifiable Health

Information, 45 CFR Parts 160, 162, and 184 (HIPAA), provisions of the HITECH Act, Title XIII,

Subtitle' D, Parts 1&2 of the American Recovery and Reinvestment Act of 2009, 42 USC 17934,

et sec., applicable to business associates, and as applicable, to be bound by the provisions of

the Confidentiality of Substance Use Disorder Patient Records, 42 USC s. 290 dd-2, 42 CFR Part

2, (Part 2), as any of these laws and regulations may be amended from time to time.

(1) Definitions

a. The following terms shall have the same meaning as defined In HIPAA, the HITECH

Act, and Part 2, as they may be amended from time to time:

"Breach," "Designated Record Set," "Data Aggregation," Designated Record

Set," "Health Care Operations," "HITECH Act," "Individual," "Privacy Rule,"

"Required by law," "Security Rule," and "Secretary."

b. Business Associate Agreement, (BAA) means the Business Associate Agreement

that includes privacy and confidentiality requirements of the Business Associate

working with PHI and as applicable. Part 2 record{s) on behalf of the Covered Entity

under the Agreement.

c. "Constructively Identifiable," means there is a reasonable basis to believe that the

information could be used, alone or in combination with other reasonably available

information, by an anticipated recipient to identify an individual who is a subject of

the information.

d. "Protected Health Information" ("PHI") as used In the Agreement and the BAA,

means protected health information defined in HIPAA 45 CFR 160.103, limited to

the information created, received, or used by Business Associate from or on behalf

of Covered Entity, and includes any Part 2 records, if applicable, as defined below.

e. "Part 2 record" means any patient "Record," relating to a "Patient," and "Patient

Identifying Information," as defined in 42 CFR Part 2.11.

f. "Unsecured Protected Health Information" means protected health Information that

is not secured by a technology standard that renders protected health information

unusable, unreadable, or indecipherable to unauthorized individuals and Is

developed or endorsed by a standards developing organization that is accredited

by the American National Standards Institute.

(2) Business Associate Use and Disclosure of Protected Health Information

a. Business Associate shall not use, disclose, maintain, store, or transmit Protected

Health Information (PHI) except as reasonably necessary to provide the services

Ut-liMilti

m

Contractor Initials ^

Business Associate Agreement

outlined under the Agreement. Further, Business Associate, including b

Exhibit E

S/16/2025

Date

V2.0.

Docusign Envelope 10:16D4D899-A91F-4EB7-899B-D710849S4A62

New Hampshire Department of Health and Human

Exhibit E

limited to all its directors, officers, employees, and agents, shall protect any PHI as

required by HIPPA and 42 CFR Part 2, and not use, disclose, maintain, store, or

transmit PHI in any manner that would constitute a violation of HIPAA or 42 CFR

Part 2.

b. Business Associate may use or disclose PHI, as applicable;

I. For the proper management and administration of the BusinessAssociate;

II. As required bylaw, according to the terms set forth In paragraph c. and d. below;

III. According to the HIPAA minimum necessary standard;

IV. For data aggregation purposes for the health care operations of the Covered

Entity; and

V. Data that is de-identified or aggregated and remains constructively identifiable

may not be used for any purpose outside the performance of the Agreement.

c. To the extent Business Associate is permitted under the BAA or the Agreement to

disclose PHI to any third party or subcontractor prior to making any disclosure, the

Business Associate must obtain, a business associate agreement or other

agreement with the third party or subcontractor, that complies with HIPAA and

ensures that all requirements and restrictions placed on the Business Associate as

part of this BAA with the Covered Entity, are included in those business associate

agreements with the third party or subcontractor.

d. The Business Associate shall not, disclose any PHI in response to a request or

demand for disclosure, such as by a subpoena or court order, on the basis that it

is required by law. without first notifying Covered Entity so that Covered Entity can

determine how to best protect the PHI. If Covered Entity objects to the disclosure,

• the Business Associate agrees to refrain from disclosing the PHI and shall

cooperate with the Covered Entity in any effort the Covered Entity undertakes to

contest the request for disclosure, subpoena, or other legal process. If applicable

relating to Part 2 records, the Business Associate shall resist any efforts to access,

part 2 records in any judicial proceeding.

(3) Obligations and Activities of Business Associate

a. Business Associate shall implement appropriate safeguards to prevent

unauthorized use or disclosure of all PHI in accordance with HIPAA Privacy Rule

and Security Rule with regard to electronic PHI, and Part 2, as applicable.

b. The Business Associate shall immediately notify the Covered Entity's Privacy

Officer at the following email address, DHHSPrivacyOfficer(S)dhhs.nh.gov after the

Business Associate has determined that any use or disclosure not provided for by

its contract, including any known or suspected privacy or security incident or breach

has occurred potentially exposing or compromising the PHI. This includes

inadvertent or accidental uses or disclosures or breaches of unsecured protected

health information.

c. In the event of a breach, the Business Associate shall comply with the terms of this

Business Associate Agreement, all applicable state and federal laws and

regulations and any additional requirements of the Agreement.

d. The Business Associate shall perform a risk assessment, based on the information

available at the time it becomes aware of any known or suspected priv^nifir

m. Exhibit E

Contractor Initials

Business Associate Agreement

„ 5/16/2025

■ V2.0

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human

Exhibit E

security breach as described above and communicate the risk assessment to the

Covered Entity. The risk assessment shall include, but not be limited to:

I. The nature and extent of the protected health Information involved, including the

types of identifiers and the likelihood of re-identification;

II. The unauthorized person who accessed, used, disclosed, or received the

protected health information;

III. Whether the protected health information was actually acquired or viewed; and

IV. How the risk of loss of confidentiality to the protected health information

has been mitigated.

e. The Business Associate shall complete a risk assessment report at the conclusion

of its incident or breach investigation and provide the findings in a written report to

the Covered Entity as soon as practicable after the conclusion of the Business

Associate's investigation.

f. Business Associate shall make available all of its internal policies and procedures,

books and records relating to the use and disclosure of PHI received from, or

created or received by the Business Associate on behalf of Covered Entity to the

US Secretary of Health and Human Services for purposes of determining the

Business Associate's and the Covered Entity's compliance with HIPAA and the

Privacy and Security Rule, and Part 2, if applicable.

g. Business Associate shall require all of its business associates that receive, use or

have access to PHI under the BAA to agree in writing to adhere to the same

restrictions and conditions on the use and disclosure of PHI contained herein.

h. \A/ithin ten (10) business days of receipt of a written request from Covered Entity,

Business Associate shall make available during normal business hours at its offices

all records, books, agreements, policies and procedures relating to the use and

disclosure of PHI to the Covered Entity, for purposes of enabling Covered Entity to

determine Business Associate's compliance with the terms of the BAA and the

Agreement.

i. Within ten (10) business days of receiving a written request from Covered Entity,

Business Associate shall provide access to PHI in a Designated Record Set to the

Covered Entity, or as directed by Covered Entity, to an individual in order to meet

the requirements under 45 CFR Section 164.524.

j. Within ten (10) business days of receiving a written request from Covered Entity for

an amendment of PHI or a record about an individual contained in a Designated

Record Set, the Business Associate shall make such PHI available to Covered

Entity for amendment and incorporate any such amendment to enable Covered

Entity to fulfill its obligations under 45 CFR Section 164.526.

k. Business Associate shall document any disclosures of PHI and information related

to any disclosures as would be required for Covered Entity to respond to a request

by an individual for an accounting of disclosures of PHI in accordance with 45 CFR

Section 164.528.

I. Within ten (10) business days of receiving a written request from Covered Entity for

a request for an accounting of disclosures of PHI, Business Associate shall make

available to Covered Entity such information as Covered Entity may require

its obligations to provide an accounting of disclosures with respect to RFIT mExhibit E [Contractor Initials

Business Associate Agreement

^^^16/2025

V2.0

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

New Hampshire Department of Health and Human

Exhibit E

accordance with 45 CFR Section 164.528.

m. In the event any individual requests access to, amendment of, or accounting of PHI

directly from the Business Associate, the Business Associate shall within five (5)

business days fonward such request to Covered Entity. Covered Entity shall have

the responsibility of responding to forwarded requests. However, If forwarding the

individual's request to Covered Entity would cause Covered Entity or the Business

Associate to violate HIPAA and the Privacy and Security Rule, the Business

Associate shall instead respond to the individual's request as required by such law

arid notify Covered Entity of such response as soon as practicable.

n. Within thirty (30) business days of termination of the Agreement, for any reason,

the Business Associate shall return or destroy, as specified by Covered Entity, all

PHI received from or created or received by the Business Associate in connection

with the Agreement, and shall not retain any copies or back-ups of such PHI in any

form or platform.

VI. If return or destruction is not feasible, or the disposition of the PHI has been

otherwise agreed to in the Agreement, or if retention is governed by state

or federal law. Business Associate shall continue to extend the protections

of the Agreement, to such PHI and limit further uses and disclosures of such

PHI to those purposes that make the return or destruction infeasible for as

long as the Business Associate maintains such PHI. If Covered Entity, in its

sole discretion, requires that the Business Associate destroy any or all PHI,

the Business Associate shall certify to Covered Entity that the PHI has been

destroyed.

(4) dblioatlons of Covered Entitv

a. Covered Entity shall post a current version of the Notice of the Privacy Practices

on the Covered Entity's website;

https://www.dhhs.nh.gov/oos/hipaa/publications.htm in accordance with 45 CFR

Section 164.520.

b. Covered Entity shall promptly notify Business Associate of any changes in, or

revocation of permission provided to Covered Entity by individuals whose PHI may

be used or disclosed by Business Associate under this BAA, pursuant to 45 CFR

Section 164.506 or 45 CFR Section 164.508.

c. Covered entity shall promptly notify Business Associate of any restrictions on the

use or disclosure of PHI that Covered Entity has agreed to in accordance with 45

CFR 164.522, to the extent that such restriction may affect Business Associate's

use or disclosure of PHI.

(5) Termination of Agreement for Cause

a. In addition to the General Provisions (P-37) of the Agreement, the Covered Entity

may immediately terminate the Agreement upon Covered Entity's knowledge of a

material breach by Business Associate of the Business Associate Agreement. The

Covered Entity may either immediately terminate the Agreement or provide an

opportunity for Buisiness Associate to cure the alleged breach within a timeframe

specified by Covered Entity.

(6) Miscellaneous / IniUal

usecTa. Definitions, Laws, and Regulatory References. All laws and regulations

Exhibit E

Contractor Initials.

Business Associate Agreement

5/16/2025

Date

V2.0

Docusign Envelope ID; 16D4D899-A91F-4EB7-899B-D710W984A62

New Hampshire Department of Health and Human

Exhibit E

herein, shall refer to those laws and regulations as amended from time to time. A

reference in the Agreement, as amended to include this Business Associate

Agreement, to a Section in HIPAA or 42 Part 2, means the Section as in effect or

as amended.

b. Change In law - Covered Entity and Business Associate agree to take such action

as is necessary from time to time for the Covered Entity and/or Business Associate

to comply with the changes in the requirements of HIPAA, 42 CFR Part 2 other

applicable federal and state law.

c. Data Ownership - The Business Associate acknowledges that it has no ownership

rights with respect to the PHI provided by or created on behalf of Covered Entity.

d. Interpretation - The parties agree that any ambiguity in the BAA and the

Agreement shall be resolved to permit Covered Entity and the Business Associate

to comply with HIPAA and 42 CFR Part 2.

e. Seareaatlon - If any term or condition of this BAA or the application thereof to any

person(s) or circumstance is held invalid, such invalidity shall not affect other terms

or conditions which can be given effect without the invalid term or condition; to this

end the terms and conditions of this BAA are declared severable.

f. Survival - Provisions in this BAA regarding the use and disclosure of PHI, return

or destruction of PHI. extensions of the protections of the BAA in section (3) g. and

(3) n.l., and the defense and indemnification provisions of the General Provisions

{P-37) of the Agreement, shall survive the termination of the BAA.

IN WITNESS WHEREOF, the parties hereto have duly executed this Business Associate

Agreement.

Department of Health and Human Services occupational Health Centers of the southwest,

The State

OoeuSigrved by:

Name of the Contractor

«ni

Signature of Authorized RepresentativeSignature of Authorized Representative

Ellen Lapointe Robert G. Hassett, do, mph

Name of Authorized Representative Name of Authorized Representative

chief Executive Officer President, Treasurer & Corp. secretary

Title of Authorized Representative Title of Authorized Representative

5/20/2025 5/16/2025

Date Date

Exhibit E

Business Associate Agreement

V2.0

Contractor Initials ^

5/16/2025

Date

Oocusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

State of New Hampshire

Department of State

CERTIFICATE

I, David M. Scanlan, Secretary of State of the State of New Hampshire, do hereby certify that OCCUPATIONAL HEALTH

CENTERS OF THE SOUTHWEST, P.A. is a Texas Professional Profit Corporation registered to transact business in New

Hampshire on August 12, 2005.1 further certify that all fees and documents required by the Secretary of State's office have been

received and is in good standing as far as this office is concerned.

Business ID: 542307

Certificate Number: 0007170008

u.

<fe5>

IN TESTIMONY WHEREOF,

1 hereto set my hand and cause to be affixed

the Seal of the State of New Hampshire,

this 28th day of April A.D. 2025.

David M. Scanlan

Secretary of State

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

CERTIFICATE OF AUTHORITY

Concentra Health Services, Inc.. the managing entity over Occupational Health Centers of the Southwest,

P.A. does hereby certify that:

1. I am a Vice President and Assistant Secretary of Concentra Health Services, Inc., the managing

entity over Occupational Health Centers of the Southwest, P.A.

2. That Robert Hassett, D.O, Is hereby authorized on behalf of this company to enter into said

contracts with the State, and to execute any and all documents, agreements, and other

instruments, and any amendments, revisions, or modifications thereto, as he/she may deem

necessary, desirable or appropriate, and Robert Hassett, D.O, is the 100% owner of Occupational

Health Centers of the Southwest, P.A.

3. I further certify that it is understood that the State of New Hampshire will rely on this certificate

as evidence that the person listed above currently occupies the position indicated and that they

have full authority to bind the company. This authorization was valid thirty (30) days prior to and

remains valid for thirty (30) days from the date of this certificate.

y—sign*

I Skf'

8lgn«d by:

'AlAAL d. DlMa. 5/1/2025

Name: Stefanie Dean Date

Title: VP and Assistant Secretary

Company Name: Concentra Health Services, Inc.

>\dc^cf CERTIFICATE OF LIABILITY INSURANCE DATE (MM/DD/YYYY).

5/6/2025

THIS CERTIFICATE IS ISSUED AS A MATTER OF INFORMATION ONLY AND CONFERS NO RIGHTS UPON THE CERTIFICATE HOLDER. THIS

CERTIFICATE DOES NOT AFFIRMATIVELY OR NEGATIVELY AMEND, EXTEND OR ALTER THE COVERAGE AFFORDED BY THE POLICIES

BELOW. THIS CERTIFICATE OF INSURANCE DOES NOT CONSTITUTE A CONTRACT BETWEEN THE ISSUING INSURER(S), AUTHORIZED

REPRESENTATIVE OR PRODUCER. AND THE CERTIFICATE HOLDER.

IMPORTANT: If the certificate holder Is an ADDITIONAL INSURED, the pollcy(le8) must have ADDITIONAL INSURED provisions or be endorsed.

If SUBROGATION IS WAIVED, subject to the terms and conditions of the policy, certain policies may require an endorsement. A statement on

this certificate does not confer rights to the certificate holder in lieu of such endorsement(s).

PPODUCER

Graham Company,

a Marsh & McLennan Agency, LLC company

30 S 15th Street, 20th Floor

Philadelphia PA 19102

NAME*^^ Concentra Unit

215-567-6300 HoV 215-105-2694

!nnRF«5s. Concentra Unit®arahamco.com

INSURER(S) AFFORDING COVERAGE NAICH

INSURER A: Columbia Casualty Comoanv 31127

INSURED C0NCGR04>1

Occupational Health Centers of The Southwest PA

dba Concentra Medical Centers

5080 Spectrum Drive, Suite 1200 West

Adfjison TX 75001

INSURER a: Liberty Mutual Fire Ins. Co. 23035

INSURER c: Allied World Assurance Comoanv. AG

INSURER 0: Emolovers Insurance of Wausau 21458

INSURER E: LM Insurance CorDoration 33600

INSURER F: Liberty Insurance Corporation 42404

THIS IS TO CERTIFY THAT THE POLICIES OF INSURANCE LISTED BELOW HAVE BEEN ISSUED TO THE INSURED NAMED ABOVE FOR THE

INDICATED NOTWITHSTANDING ANY REQUIREMENT. TERM OR CONDITION OF ANY CONTRACT OR OTHER DOCUMENT WITH RESPECT TO WHICH THISCERTIFICATE MAY BE ISSUED OR MAY PERTAIN. THE INSURANCE AFFORDED BY THE POLICIES DESCRIBED HEREIN IS SUBJECT TO ALL THE TERMS,

EXCLUSIONS AND CONDITIONS OF SUCH POLICIES. LIMITS SHOWN MAY HAVE BEEN REDUCED BY PAID CLAIMS.

INSR

ilS. TYPE OF INSURANCE POLICY NUMBER

COMMERCIAL GENERAL UABIUTY

CLAIMS-MADE OCCUR

Pre(M«ion«l Ua

t1MCI«liTtf$3M Ag

GE^n. AGGREGATE UMft APPLIES PER:

PoucvDSS □

OTHER:

LOG

HAZ 4032244581-9

POLICY EFF

<MM/DD^YYY1

1/1/2025

POLICY EXP

<MM/0D/YYYY1

1/1/2026

LIMITS

EACH OCCURRENCE

DAMAGE TO RENTED

PREMISES tEa occufreoca)

MED EXP (Any one p«»on)

PERSONAL & AOV INJURY

GENERAL AGGREGATE

PRODUCTS • COMP/OP AGG

S 1.000.000

S 500.000

S 1.000.000

$ 3.000.000

S 3.000.000

AUTOMOBILE LIABILITY

ANY AUTO

AS2-631-510199-32S 4/1/2025 4/1/2026 GDmbinEd Single limit

(Ea acddefill • S 2.000.000

BODILY INJURY (Per persoo)

OWNED

AUTOS ONLY

HIRED

AUTOS ONLY

UMBRELLA LIAB

EXCESS LIAB

DED

SCHEDULED

AUTOS

NON-OWNED

AUTOS ONLY

BODILY INJURY (Per acddeni)

PROPERTY damage

(Per ecddentl

OCCUR

CLAIMS-MADE

HMC 4032235752 1/1/2025 1/1/2026 EACH OCCURRENCE $9,000,000

AGGREGATE S 10.000.000

RETENTION nrw

WORKERS COMPENSATION

AND EMPLOYERS' LIABILITY y / N

ANYPROPRIETORff'ARTNER«XECUTIVE

OFFICER/MEMBEREXCLUDEO?

(Mandatory In NH)

If yes. describe under

* * below

f yes. describe under

DESCRIPTION OF OPERATIONS I

WA7-63D-510199-355

WA5-63D-510199-315

4/1/2025

4/1/2025

4/1/2026

4/1/2026

PER

STATUTE

■StFT

ER

N/A

E.L. EACH ACCIDENT S 1.000.000

E.L DISEASE • EA EMPLOYEE S 1.000.000

E.L. DISEASE • POLICY LIMIT $ 1.000.000

Property

Excess Liability

YAC-L9L-477341-015

C023701/010

1/1/2025

1/1/2025

1/1/2026

1/1/2026

SEE BELOW

S10M Each (Occurrence S10M Aggregate

DESCRIPTION OF OPERATIONS/ LOCATIONS / VEHICLES (ACORO 101. AddlOonal Remarks Schedule, may be attached Kmore Space Is. »

PRIMARY LIABILTY POLICY includes General Liability Coverage on an Occurrence Basis and Professional Liability Coverage on a Claims Made uasis.

UMBRELLA LIABILlPi' COVERAGE includes Excess General Liability on an Occurrence Basis and Excess Professional Liability on a Claims Made Basis.Both Coverages are excess of a S3,000.000 Self-Insured Retention each Occurrence/Claim subject to a $18,000,000 Aggregate.

INDIANA PHYSICIAN PROFESSIONAL LIABILITY COVERAGE - Continental Casualty Company - Policy #HAZ 4032244595-11: Effective 1/1/2025-1/1/2026$500,000 Each Medical Incident/Si. 500.000 Aggregate Per Insured or Surgeon

See Attached...

State of NH Department of Health and Human Services

129 Pleasant Street

Concord NH 03301-3857

1 ^

SHOULD ANY OF THE ABOVE DESCRIBED POLICIES BE CANCELLED BEFORE

THE EXPIRATION DATE THEREOF, NOTICE WILL BE DELIVERED IN

ACCORDANCE WITH THE POLICY PROVISIONS.

ACORD 25(2016/03) The ACORD name and logo are registered marks of ACORD

Docusign Envelope ID: 16D4D899-A91F-4EB7-899B-D71084984A62

AGENCY CUSTOMER ID: CONCGRO-01

LOC0;

A^cORcf ADDITIONAL REMARKS SCHEDULE Page i of i

AGENCY

Graham Company.

NAMED INSURED

Occupational Health Centers of The Southwest PA

dba Concentre Medical Centers

5080 Spectrum Drive, Suite 1200 West

Addison TX 75001

POLICY NUMBER

CARRIER NAIC CODE

EFFECTIVE DATE:

ADDITIONAL REMARKS

THIS ADDITIONAL REMARKS FORM IS A SCHEDULE TO ACORD FORM,

pnPM NiiMBPRr 25 pnPM TiTi P- CERTIFICATE OF LIABILITY INSURANCE

KANSAS PHYSICIAN PROFESSIONAL LIABILITY COVERAGE - Continental Casualty Company • Policy #HAZ 4032244600-11; Effective 1/1/2025-1/1/2026 -

$500,000 Each Medical lnctdent/$1,500,000 Aggregate Per Insured or Surgeon

LOUISIANA PHYSICIAN PROFESSIONAL LIABILITY COVERAGE ■ Columbia Casualty Company - Policy #HAZ 4032244614-11; Effective 1/1/2025-1/1/2026 -

$100,000 Each Medical lncident/$300.000 Aggregate Per Insured or Surgeon

NEBRASKA PHYSICIAN PROFESSIONAL LIABILITY COVERAGE - Continental Casualty Company - Policy #HA2 4032244628-11; Effective 1/1/2025-1/1/2026

- $800,000 Each Medical lncident/$3,000.000 Aggregate Per Insured or Surgeon

PENNSYLVANIA PHYSICIAN PROFESSIONAL LIABILITY COVERAGE - Columbia Casualty Company - Policy #HAZ 4032244631-11; 1/1/2025-1/1/2026 -

$500,000 Each Medical lncident/$1,500,000 Aggregate Per Insured or Surgeon

V\/ISCONSIN PHYSICIAN PROFESSIONAL LIABILITY COVERAGE - Continental Casualty Company - Policy #HAZ 4032244659-11; 1/1/2025-1/1/2026 -

$1,000,000 Each Medical lncident/$3,000,000 Aggregate Per Insured or Surgeon

PROPERTY COVERAGE: Risk of Physical Loss or Damage to Covered Property subject to policy terms and conditions.

WORKERS COMPENSATION - Occupational Health Centers of California. A Medical Corporation - Liberty Mutual Insurance Corp. - Policy

#WA5-63D-510199-315; Effective: 4/1/2025-4/1/2026

WORKERS COMPENSATION - Occupational Health Centers of Southwest. P.A. - Liberty Insurance Corp. - Policy #WA7-63D-510199-405; Effective:

4/1/2025-4/1/2026

WORKERS COMPENSATION - Occupational Health Centers of Southwest, P.A. - Liberty Mutual Insurance Corp. - Policy #WC5-631-510199-255 (Wl);

Effective: 4/1/2025-4/1/2026

ADDITIONAL WORKERS COMPENSATION POLICIES:

OHC of Arkansas - Liberty Insurance Corp. - Policy #WC7-631-510199-285; Effective; 4/1/2025-4/1/2026

OHC of Southwrest (AZ/UT) - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-245; Effective: 4/1/2025-4/1/2026OHC of Delaware - Liberty Mutual Fire Insurance Company - Policy #V^2-631-510199-335; Effective: 4/1/2025-4/1/2026

OHC of Georgia/Hawaii - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-385; Effective; 4/1/2025-4/1/2026

OHC of Illinois - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-415; Effective; 4/1/2025-4/1/2026

OHC of Louisiana - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-295; Effective; 4/1/2025-4/1/2026

OHC of Michigan - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-275: Effective; 4/1/2025-4/1/2026

OHC of Nebraska - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-375; Effective; 4/1/2025-4/1/2026

OHC of New Jersey - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-265; Effective; 4/1/2025-4/1/2026

OHC of North Carolina - Lit>erty Insurance Corp. - Policy #WC7-631-510199-345; Effective; 4/1/2025-4/1/2026

OHC of Southwest (KS) - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-425: Effective; 4/1/2025-4/1/2026

Therapy Centers of Southwest I, PA (OR) - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-395; Effective; 4/1/2025-4/1/2026

Therapy Centers of South Carolina, PA - Liberty Mutual Fire Insurance Company - Policy »WC2-631-510199-305; Effective; 4/1/2025-4/1/2026

OHC of Minnesota - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-455; Effective; 4/1/2025-4/1/2026

OHC of Alaska - Liberty Mutual Fire Insurance Company - Policy #WC2-631-510199-445; Effective; 4/1/2025-4/1/2026

CYBER LIABILITY - /Vch Specialty Insurance Company - Policy #NPL2001106-00; Effective: 11/25/2024-11/25/2025 - Limit; $10,000,000

EXCESS CYBER LIABILITY - Homeland Insurance Company of New York - Policy #720002431-0000; Effective; 11/25/2024-11/25/2025 -

Limit: $10,000,000 Excess of $10,000,000

CRIME COVERAGE - National Union Fire Insurance Company of Pittsburgh. PA - Policy #02-173-18-50, Effective 11/25/2024-1/1/2026- Limit $10,000,000

Coverage is provided for all medical professionals currently or previously employed or contracted by the above Named Insured, but only for professional servicesperformed for or on behalf of the above Named Insured.

RE: OHC OF SWPA/CMC IS BIDDING ON RFP TO PROVIDE MEDICAL SERVICES TO THE EMPLOYEES OF THE NAMED CLIENT.

State of NH Department of Health and Human Services is an additional insureds on the above General Liability, Auto Liability and Umbrella Liability Policies ifrequired by written contract.

ACORD 101 (2008/01) ©2008 ACORD CORPORATION. All rights reserved.

The ACORD name and logo are registered marks of ACORD

Case records

Open case page

Dockets: 2026-0003, 2004-0191

Date Record Text Type Party PDF
April 24, 2026 K.P. v. O.v. Supreme Court case order Supreme Court PDF
March 4, 2026 Governor and Executive Council Agenda item PDF - 2026-03-04 - 191 GC Agenda 062525.pdf Current page Other PDF