At Physiopedia Plus, we are committed to safeguarding personal health information and ensuring full compliance with the U.S. Health Insurance Portability and Accountability Act (HIPAA). This includes adherence to the Privacy Rule, Security Rule, and Breach Notification Rule.
1. Privacy Rule Compliance
We protect the confidentiality and proper use of Protected Health Information (PHI) by:
- Ensuring PHI is accessed only by authorised individuals with a legitimate need, following the principle of minimum necessary use.
- Limiting the use and disclosure of PHI to permitted purposes, with appropriate user consent or legal authority where required.
- Providing training to all staff and contractors on HIPAA requirements and internal privacy policies.
2. Security Rule Compliance
We implement a comprehensive set of administrative, physical, and technical safeguards to secure electronic PHI (ePHI), including:
- Regular risk assessments and security audits.
- Role-based access controls and secure authentication.
- Encryption of data both at rest and in transit.
- Secure hosting environments with controlled physical access and system monitoring.
- Execution and maintenance of Business Associate Agreements (BBAs) with all vendors handling PHI.
3. Breach Notification Rule Compliance
In the unlikely event of a data breach involving unsecured PHI, we follow HIPAA’s breach notification procedures:
- Assess the scope and impact of the breach through a formal risk analysis.
- Notify affected individuals and the U.S. Department of Health and Human Services (HHS), in accordance with HIPAA timelines.
- Take corrective actions to mitigate risks and prevent future incidents.