NASH PKI Certificate for Healthcare Provider Organisations renewal confirmation



Similar documents
USER AGREEMENT FOR: ELECTRONIC DEALINGS THROUGH THE CUSTOMS CONNECT FACILITY

TEXTURA AUSTRALASIA PTY LTD ACN ( Textura ) CONSTRUCTION PAYMENT MANAGEMENT SYSTEM TERMS AND CONDITIONS OF USE

Electronic business conditions of use

(This agreement is in rich text format and appears in a scrolling text box once you ve reached

Terms and Conditions for Online Services of BOC Credit Card (International) Limited

BOC Credit Card (International) Limited - Terms and Conditions for Online Services

ELECTRONIC TRADING FACILITIES SUPPLEMENTAL TERMS AND CONDITIONS OF TRADING

Soltec Computer Systems Limited ( THE COMPANY ) Suite 1 Castlethorpe Court, Castlethorpe, Brigg, North Lincolnshire, DN20 9LG

Custodian-Node data provision terms and conditions

Rothschild Visa Card Terms and Conditions

IP AUSTRALIA B2B ONLINE TRANSACTION SYSTEM AGREEMENT

AdvantageCard Rewards Program. Terms & Conditions - Business

GlobalSign Subscriber Agreement for DocumentSign Digital ID for Adobe Certified Document Services (CDS)

Clause 1. Definitions and Interpretation

TELSTRA RSS CA Subscriber Agreement (SA)

1.3 Your access to and use of the Site, including your order of Products through the Site, is subject to these terms and conditions.

CCMS Software Provider Business Assurance Statement Deed Poll

W.H. Software Maintenance and Technical Support Agreement

"Certification Authority" means an entity which issues Certificates and performs all of the functions associated with issuing such Certificates.

APPLICANT VERIFICATION SERVICES TERMS AND CONDITIONS OF USE

TRACKER. Terms and Conditions

The New South Wales Prize System

Capitalized terms not defined below shall have the meaning given to them in the applicable CP/CPS, unless the context requires otherwise.

Reckon Tools Backup licence agreement

TERMS OF USE FOR PUBLIC LAW CORPORATION PERSONAL CERTIFICATES FOR QUALIFIED DIGITAL SIGNATURE

Amazon Trust Services Certificate Subscriber Agreement

Standard conditions of purchase

TERMS OF USE TITLE CERTIFICATES FOR ELECTRONIC SIGNATURE

THE PUBLIC RELATIONS CONSULTANTS ASSOCIATION. Find A PR agency Terms and Conditions for Clients

TERMS OF USE FOR NOTARIAL PERSONAL REPRESENTATION CERTIFICATES FOR AUTHENTICATION

DOMAIN NAME REGISTRATION SERVICES TERMS AND CONDITIONS

MarketPlace Leichhardt VIP Cashback Card and Loyalty Program Terms and Conditions Issued 5 December 2013

GlobalSign Subscriber Agreement for PersonalSign and DocumentSign for Adobe CDS Certificates Combined Agreement for epki (US)

TERMS AND CONDITIONS GOVERNING THE USE OF NBADS ONLINE TRADING

RapidSSL Subscriber Agreement

Luxbet CASH OUT TERMS AND CONDITIONS ( Luxbet Cash Out T&Cs )

Authorized Subscribers

2015 Commonwealth Bank Staff Community Fund Community Grants Grant Guidelines

TELEPHONY AND I.T ORDER FORM

Our terms and conditions which all customers have to agree to are as follows:

VET (WA) Ministerial Corporation Purchase of Training Services Process Terms and Conditions

Terms and Conditions for the Registration of Domain Names

Macquarie Rewards Program. Terms and Conditions

ARTL PKI. Certificate Policy PKI Disclosure Statement

MOBILE SERVICES AGREEMENT. Effective Date: 11 April 2013

THE VODAFONE HOMECOACH GAME PROMOTION CONDITIONS OF ENTRY

If you are unclear about the implications of Auto Enrolment you will find our Guide to Auto Enrolment a good starting point.

David Jones Storecard and David Jones American Express Card Member Agreement, Financial Services Guide and Purchase Protection. Terms and Conditions

TERMS OF USE 1 DEFINITIONS

UBS Electronic Trading Agreement Global Markets

(Short Form) Terms and Conditions. Version 1.2 dated 17 February Please note:

Website Terms and Conditions

If you are in full agreement with the document, kindly return the signature page at the end of the documents

Foreign Payments Private Client Application Form

GEOSURE PROTECTION PLAN

Conditions of Supply of Internet Services

SOFTWARE DEVELOPMENT AGREEMENT

ODETTE CA Subscriber Agreement for Certificates

TERMS AND CONDITIONS FOR PERSONAL INTERNET BANKING - DIGITAL BANKING

TERMS AND CONDITIONS FOR ANZ BANK ACCOUNT SECTION III TERMS AND CONDITIONS FOR PERSONAL INTERNET BANKING - DIGITAL BANKING

MISSOURI HIGHWAYS AND TRANSPORTATION COMMISSION ELECTRONIC SIGNATURE AGREEMENT

BUSINESS ONLINE BANKING AGREEMENT

Any owner or authorized signer of any Account may obtain a separate Access ID and Password for access to such Account.

PESKY GNATS CLINICIAN LICENSING AGREEMENT

2. Our Conditions 2.1 When They Apply 2.2 Deposit 2.3 Your Account and On Line Sign Up 2.4 Minimum Period of Service 2.

HKUST CA. Certification Practice Statement

Bendigo Rewards. Terms & Conditions. 21 December

TERMS AND CONDITIONS OF USE OF KUWAIT FINANCE HOUSE BAHRAIN S WEBSITE & INTERNET BANKING SERVICES

ANZ Expense Manager TERMS AND CONDITIONS 03.10

Business Banking Online application.

Commercial Online Banking

GlobalSign Subscriber Agreement for DomainSSL Certificates

Certification Practice Statement (ANZ PKI)

ONLINE BACKUP SERVICE SUBSCRIPTION AGREEMENT

COMPREHENSIVE REMOTE ACCESS AGREEMENT FOR PRIVATE MEDICAL PRACTICES OR NURSING HOMES

Viva Energy may from time to time amend, delete or supplement these Terms and Conditions. Any change takes effect from the earlier of:

Software Support and Maintenance Terms

1.1 These Terms and Conditions set out the agreement between MRS Web Solutions Ltd, 1 Blue Prior Business Park, Redfields Ln, Church Crookham,

Acquia Certification Program Agreement

Terms and Conditions. Terms & Conditions. 1. Definitions. 2. Use of the website. 3. Privacy. 4. Purchase of products & gift vouchers

(the "Website") is provided by Your Choice Counselling.

BROOKFIELD GLOBAL INTEGRATED SOLUTIONS STANDARD PURCHASE ORDER TERMS FOR SUPPLIES

Team Anywhere ORDER FORM

Trinity Online Application - Terms and Conditions of Use

Vodafone Group Certification Authority Test House Subscriber Agreement

LET S ENCRYPT SUBSCRIBER AGREEMENT

App Terms and Conditions!

GENOA, a QoL HEALTHCARE COMPANY GENOA ONLINE SYSTEM TERMS OF USE

VIRTUAL OFFICE WEBSITE LICENSE AGREEMENT

International Payment Service Terms and conditions

MRMLS LISTING INFORMATION LICENSE AGREEMENT

Terms and Conditions Maybank Private Banking Account/ Maybank Private Banking Account-i. Member of PIDM

Certification Exam or Test shall mean the applicable certification test for the particular product line or technology for which You have registered.

We suggest you retain a copy of these End User Terms of Use for your records.

This Agreement (herein after called "Agreement") is made on the day of, 20 in by and between:

APPLICATION FOR DIGITAL CERTIFICATE

MUSIC RESOURCES TERMS AND CONDITIONS FOR SCHOOLS ( Conditions )

These Terms and Conditions supersede all previous Terms and Conditions

Entee Global Services General Terms and Conditions

WEBSITE TERMS OF USE

Transcription:

NASH PKI Certificate for Healthcare Provider Organisations renewal confirmation Please send your completed renewal confirmation to: Department of Human Services Fax number: 1800 890 698 Number of pages (including this page): Or Scan and Email: nash.pki@humanservices.gov.au Title: Dr [_] Mr [_] Mrs [_] Ms [_] Miss [_] Other [ ] Family Name: Given Name(s): Fax: Phone: Registration Authority number: I would like to renew my organisation s NASH PKI Certificate and agree for my organisation s legal entity to be bound by the enclosed National Authentication Service for Health (NASH) PKI Certificate for Healthcare Provider Organisation Terms and Conditions of Use and relying party agreement. Signature Date

1) In consideration of the accepting of receipt of the National Authentication Service for Health (NASH) Public Key Infrastructure (PKI) Certificate of Healthcare Provider Organisations (Application), the Organisation s legal entity (in these Terms and Conditions called the Organisation ) agrees in relation to any NASH PKI Certificate for Healthcare Provider Organisations (Certificate) provided to it on a compact disc (CD) in response to the Application that: a) The Organisation will comply with these Terms and Conditions of Use (Terms and Conditions) and the terms of the NASH PKI Relying Party Agreement including the obligations in it on the part of the Relying Party. For more information go to our website humanservices.gov.au/pki b) The versions current from time to time of the Commonwealth Department of Human Services Community of Interest Certificate Policy for the National Authentication Service for Health PKI Certificate for Healthcare Provider Organisations and the documents mentioned in it that are published by the Department of Human Services on or linked to its website govern its use of the Certificate as if set out in these Terms and Conditions c) The Organisation is responsible for uploading the Certificates from the CD onto its operating system d) The Certificate will only be used for purposes authorised or approved by Department of Human Services. Any other use of the Certificate will be at its own risk e) The Organisation is responsible for ensuring that: i. the manner of approval and signing of any message payload using the Certificate meets legal, policy and professional requirements in respect of that payload ii. it has policies and procedures for the use of the Certificate, Keys and digital signatures generated using a Key attached to a Certificate by anyone acting under or through it or as its agent or representative that enables the individuals who have used the Certificate and Keys to be identified in respect of each use and the role they iii. performed in respect of that use those policies and procedures are known and understood by everyone acting under or through it or as its agent or representative in respect of the Certificate, Keys and digital signatures generated using a Key attached to a Certificate f) The Organisation will take all reasonable measures to keep its Certificate and the CD secure at all times and take all necessary precautions to prevent its loss, disclosure, modification or unauthorised use g) The Organisation will not give its Certificate or CD to any other entity or organisation or allow any unauthorised person to use them, except for any outsourced information technology service provider engaged by it to act as its agent in using its Certificate h) The Organisation will promptly notify the Department of Human Services of the possible loss, destruction or theft of its Certificate i) The Organisation will promptly notify the Department of Human Services in the event that the Organisation considers or suspects that its Certificate has been compromised j) The Organisation may request revocation of its Certificate at any time by written notice to the Department of Human Services The Organisation s use of its Certificate may be suspended or revoked by the Department of Human Services in its absolute discretion, including but not limited to: National Authentication Service for Health Public Key Infrastructure Certificate for Healthcare Provider Organisations Terms and Conditions of Use i. after loss, destruction or theft of the Certificate ii. in the event of its de- registration (however described) iii. in the event the Healthcare Identifier service operator established under the Healthcare Identifiers Act 2010 cancels its HPI-O iv. in the event that the Organisation revokes any consent given under section 24A of the Healthcare Identifiers Act 2010 or alters any limitations regarding the consent k) The Organisation will immediately notify the Department of Human Services upon becoming aware that any of the circumstances when its Certificate may be suspended or revoked has occurred l) Revocation of the Organisation s Certificate does not automatically terminate these Terms and Conditions m) All information the Organisation provides and representations the Organisation makes to the Department of Human Services are complete and accurate n) The Organisation will promptly notify the Department of Human Services in the event that Organisation considers any information provided, or representations made by it, is or may be incorrect o) Any use of the Organisation s Certificate by any other person as a result of a breach of these Terms and Conditions by the Organisation will be deemed to be a use of the Certificate by the Organisation p) Each of the Department of Human Services and the Organisation may terminate these Terms and Conditions at any time by giving a written notice to the other party. The Organisation agrees that the Organisation will not be able to and will not conduct communications using its Certificate after termination q) If these Terms and Conditions are terminated, the Organisation s obligations will continue in respect of any electronic communications the Organisation made using its Certificate before the date of termination r) The Department of Human Services responsibility for any costs, losses or damage the Organisation (or people acting on its behalf) incur associated directly or indirectly with its use of its Certificate is subject to and limited by the Commonwealth Department of Human Services Community of Interest Certificate Policy for the National Authentication Service for Health PKI Certificate for Healthcare Provider Organisations and the documents mentioned in it described above s) The Department of Human Services may change or add to these Terms and Conditions at any time, by giving the Organisation notice by mail, by fax or electronically. A message sent to the Organisation s business email address (as held in Department of Human Services records) is one way of giving the Organisation notice electronically t) When the Organisation uses its Certificate after the Organisation has been notified of a change or addition to these Terms and Conditions, the Organisation will be taken to have agreed to the change or addition in respect of all uses of its Certificate after that date. These Terms and Conditions may not be otherwise changed orally or by conduct by the Organisation. 2. These Terms and Conditions are issued under and are to be construed in accordance with the laws in force from time to time in the Australian Capital Territory and the parties agree to submit to the courts having jurisdiction in the Australian Capital Territory. Page 2 of 7

National Authentication Service for Health Public Key Infrastructure Relying Party Agreement Parties Commonwealth of Australia as represented by the Australian Government Department of Human Services (Human Services) Relying Party, being a Relying Party within the meaning of a Human Services Health Sector PKI Certificate Policy concerning the National Authentication Service for Health (Relying Party) Definitions and interpretation 1. In this agreement: a) unless otherwise indicated, capitalised expressions have the same meanings as apply in the Human Services Health Sector PKI Certificate Policy concerning the National Authentication Service for Health (NASH) under which the Certificate being relied on has been issued b) "Certificate" means a Certificate issued under a Human Services Health Sector PKI Certificate Policy concerning the NASH c) "Clinical" means anything that relates to the examination, diagnosis or treatment of individual patients by healthcare providers who are duly qualified, registered, recognised or trusted as performing those actions. d) "ehealth Record System" means the PCEHR system under the Personally Controlled Electronic Health Records Act 2012 (Cth). e) "HI Service" means, for the purposes of this agreement, the healthcare identifiers service operated by the Chief Executive Medicare as the service operator under the Healthcare Identifiers Act 2010 (Cth), and includes the administrative extensions to that service for the registration of Supporting Organisations by Human Services f) "Intermediary" means an information technology provider that is a Relying Party and a Subscriber, and is engaged by a healthcare provider organisation for sending and receiving secure messages g) "NASH Directory" means a directory on which Human Services or its outsourced service provider publishes Certificates concerning NASH h) OCSP Responder" has the meaning provided in clause 2 i) "Subscriber" means the person that is the subscriber to, and the subject of, a Certificate; j) "Subscriber Terms and Conditions" has the meaning provided in clause 4; and Page 3 of 7

k) references to documents are to the versions that are current from time to time. Commencement and duration 2. In consideration for the PKI facility provided by Human Services that enables the Relying Party to rely on Certificates, the Relying Party acknowledges the terms and conditions on which it may so rely on Certificates, and this agreement will bind the Relying Party when it first: a) relies upon a Certificate b) uses a Key attached to a Certificate c) authenticates a digital signature using a Key attached to a Certificate; or d) accesses the NASH Directory, Certificate Revocation List or the Online Certificate Status Protocol Responder (OCSP Responder). 3. This agreement will continue to bind the Relying Party if and for so long as it asserts any reliance upon a Certificate or digital signatures generated using Keys attached to a Certificate. If the Relying Party does not agree with the terms of this agreement it must not rely on a Certificate or a digital signature generated using a Key attached to a Certificate. Subscriber Terms and Conditions 4. This agreement binds the Relying Party in addition to any terms and conditions that bind it as a Subscriber for a Certificate (Subscriber Terms and Conditions) and in addition to the applicable Certificate Policy. Authorised reliance 5. A Certificate does not verify or represent that the Subscriber is a particular organisation or a particular individual. The meaning of a Certificate is nothing more and nothing less than a statement expressed in a digital format of the fact that the Subscriber is recorded as being registered with the HI Service. 6. A Certificate does not verify or represent that the Subscriber is registered with the ehealth Record System. This registration is a separate process that may only be taken by those organisations that are eligible for that registration. 7. The Relying Party may only rely upon a Certificate or digital signature generated using a Key attached to a Certificate for purposes authorised or approved by Human Services and published at humanservices.gov.au, including as authorised by the Certificate Policy under which it was issued. Any other reliance is at the sole risk of the Relying Party. Without prejudice to the generality of that limitation, messaging between parties that is not authorised by the Certificate Policy is at the sole risk of those parties. 8. Without limiting clause 7, Relying Parties must not use a NASH PKI Certificate by itself, Page 4 of 7

and must use means other than reliance on the NASH PKI, to determine whether they will rely on the content of an electronic message or communication (including any Clinical statement or representation). Responsibility to take precautionary steps 9. The Relying Party must (either itself or if it is a healthcare provider organisation through its Intermediary, if any) before relying on a Certificate (including a reliance for encryption purposes) or a digital signature generated using a Key attached to a Certificate: a) verify the validity of a Certificate (i.e. verify that the Certificate is current and hasn t been revoked, by checking the Certificate Revocation List or querying the OCSP Responder) b) check that the Subject of the Certificate identifies sending parties of an electronic communication who have used their Certificate for digital signing c) check that the Subject of the Certificate identifies receiving parties of an electronic communication who have had their Certificate used for digital encryption d) check that the intended use of the Certificate and digital signatures generated using Keys attached to the Certificate are for purposes authorised by the Certificate Policy under which it was issued. 10. The Relying Party must act reasonably in all the relevant circumstances where relying on a Certificate or a digital signature generated using a Key attached to a Certificate, including taking reasonable precautionary steps to address risk to the Relying Party from this reliance. Without limiting this requirement, Human Services may choose to publish (and maintain) information about what it considers to be reasonable precautionary steps at humanservices.gov.au/pki. 11. If the Relying Party doesn t comply with clauses 9 and 10, any reliance upon a Certificate or a digital signature generated using a Key attached to a Certificate is solely at its own risk. Acknowledgement regarding compromised keys 12. The Relying Party acknowledges that if a Private Key is compromised or stolen the messages sent and received using it will not be reliable or secure. Human Services cannot verify whether at any particular moment in time a Private Key has been compromised or stolen. The Relying Party must promptly notify Human Services in the event that it suspects that there has been a compromise of the Subscriber s Private Key. Proper and lawful use 13. The Relying Party must not perform any improper or unlawful act in connection with its use of a Certificate. The Relying Party acknowledges that a Certificate doesn t create or vest any authorisation to perform any act in connection with it, except as expressly stated in the Page 5 of 7

applicable Certificate Policy. No agency 14. The Relying Party isn t an agent or representative of the Certification Authority or Human Services. Exclusion of liability 15. The Commonwealth of Australia is not liable for any unauthorised, improper, negligent or unlawful use by the Relying Party or any other party of a Certificate or Key attached to a Certificate. The exclusions of liability and limitations of liability provisions contained in the Subscriber Terms and Conditions, applicable Certificate Policy, Root Certification Authority Certificate Policy, Root Certification Authority Certificate Practice Statement or Organisation Certification Authority Certificate Practice Statement apply to this agreement as if set out in it, with such changes as may be necessary to give them full force and effect. Disclaimer and exclusion 16. The Commonwealth of Australia does not represent or warrant that any particular information technology provider s system (or component of their system) that is used in connection with Human Services Health Sector PKI is fit for purpose, nor does it warrant the standards of performance or product of such a system (or component of such a system) or the supplier of such a system. 17. The Commonwealth of Australia does not represent or warrant that the variable components of a Certificate that can be defined by a Subscriber (i.e. the certificate usage and organisation unit name) are correct if they are varied from the default value of 'general'. The Relying Party acknowledges that Human Services has not verified such variances to this information and as such any reliance upon that information is at the sole risk of the Relying Party. 18. The Commonwealth of Australia is not liable to the Relying Party for any damages, loss or liability incurred by the Relying Party in connection with any illness, personal injury or death arising from or in connection with the use or reliance by the Relying Party or any other person of a Certificate or Key attached to a Certificate for messaging purposes. Variations of Relying Party Agreement 19. Human Services may change or add to this agreement at any time, by giving the Relying Party notice by mail, by fax or electronically. A message sent to the Relying Party's business email address (as held in Human Services records) is one way of giving the Relying Party notice electronically. 20. When the Relying Party performs any of the acts described in clause 2 after the Relying Party has been notified of a change or addition to this agreement, the Relying Party will be Page 6 of 7

taken to have agreed to the change or addition. This agreement may not be otherwise changed orally or by conduct of the parties. Applicable law 21. This agreement is to be construed in accordance with the laws in force from time to time in the Australian Capital Territory and the parties agree to submit to the courts having jurisdiction in the Australian Capital Territory. 22. The parties intend that this agreement be legally binding on them. Page 7 of 7