Skip to content

Legal

HIPAA Compliance

Protected health information is the substance of the work we do, not an incidental part of it. This is how we treat it.

Business Associate Agreement

A Business Associate Agreement is executed with every client before services begin and before any access to protected health information is granted. No exceptions, and no work starts ahead of it.

Encrypted transmission

Protected health information is transmitted over encrypted connections and stored on encrypted systems. PHI is never sent through unsecured email or through the forms on this website.

Access controls

Named accounts only, with multi-factor authentication and least-privilege permissions in your systems. Access is scoped to the people working your account and revoked the day someone leaves it.

Audit logging

Every action is attributable to a named user. Access and activity logs are maintained and made available to you on request.

Workforce training

Everyone who touches PHI is trained on HIPAA and HITECH obligations on hire and annually thereafter, with training records retained.

Regular review

Controls are reviewed on a regular cycle and after any material change to systems or processes. If your security team has a questionnaire, send it — we would rather answer it before the contract than after.