Home Services Specialties Compliance About Contact Free A/R review

HIPAA & security

How we protect patient information

As a business associate under HIPAA and the HITECH Act, we are directly liable for how we handle your patients' protected health information. Here is exactly what that looks like in practice.

Administrative safeguards

People and process

Business Associate Agreement

A signed BAA is executed before onboarding starts and before any PHI is transmitted. It defines permitted uses, breach notification timelines, and what happens to your data when the relationship ends.

Workforce training

Every person with PHI access completes HIPAA privacy and security training at hire and annually thereafter. Training records are retained and available on request.

Minimum necessary

Staff receive access only to the records required for their assigned accounts. Access is reviewed when roles change and revoked the day someone leaves.

Subcontractor control

Any vendor that could touch PHI signs a downstream BAA. We do not offshore PHI to a subcontractor without disclosing it to you in writing first.

Incident response

A documented response plan covers containment, investigation, and notification. If a breach affects your patients, you hear it from us without undue delay and well inside the 60-day statutory window.

Sanctions policy

Policy violations carry defined consequences up to termination. Compliance is not treated as a suggestion internally.

Technical & physical safeguards

Systems and premises

Encryption

PHI is encrypted in transit using TLS 1.2 or higher and at rest using AES-256. PHI is never sent over unencrypted email or consumer messaging apps — we use secure portals or SFTP.

Access control & MFA

Unique credentials per user, multi-factor authentication on every system that stores or transmits PHI, automatic session timeout, and no shared logins.

Audit logging

System access is logged and retained. If you need to know who opened a record and when, that answer exists.

Endpoint security

Company-managed devices with full-disk encryption, endpoint protection, enforced patching, and remote wipe. No PHI on personal or unmanaged devices.

Physical security

Work areas are access-controlled with clean-desk and locked-storage requirements. Paper containing PHI is cross-cut shredded; drives are wiped or destroyed to NIST 800-88 standards.

Backup & continuity

Encrypted backups with tested restoration and a written contingency plan, so a hardware failure does not become a records-availability problem.

This website

What this site does and does not collect

Our contact forms are for business inquiries only. They are not a channel for protected health information, and we ask you never to enter patient names, dates of birth, member IDs, diagnoses, or account numbers into them.

Site traffic is served over HTTPS. Once you become a client, all PHI moves through the secure channels defined in your BAA — never through this website and never through ordinary email.

Need our security documentation?

Practices and payers are welcome to request our BAA template, policy summary, and training attestations before signing anything.