Legal
HIPAA Compliance
Protected health information is the substance of the work we do, not an incidental part of it. This is how we treat it.
Business Associate Agreement
A Business Associate Agreement is executed with every client before services begin and before any access to protected health information is granted. No exceptions, and no work starts ahead of it.
Encrypted transmission
Protected health information is transmitted over encrypted connections and stored on encrypted systems. PHI is never sent through unsecured email or through the forms on this website.
Access controls
Named accounts only, with multi-factor authentication and least-privilege permissions in your systems. Access is scoped to the people working your account and revoked the day someone leaves it.
Audit logging
Every action is attributable to a named user. Access and activity logs are maintained and made available to you on request.
Workforce training
Everyone who touches PHI is trained on HIPAA and HITECH obligations on hire and annually thereafter, with training records retained.
Regular review
Controls are reviewed on a regular cycle and after any material change to systems or processes. If your security team has a questionnaire, send it — we would rather answer it before the contract than after.