NU MD

HIPAA Notice of Privacy Practices

Notice of Privacy Practices

Required for covered healthcare entities. It explains:
  • How Protected Health Information (PHI) is used and disclosed.
  • Patient rights to access and amend records.
  • How patients can file complaints.

Technical Safeguards

HIPAA requires:
  • SSL encryption (HTTPS).
  • Secure hosting.
  • Access controls and passwords.
  • Audit logs.
  • Encrypted storage and transmission of PHI.
  • Automatic logoff and authentication procedures.

Administrative Safeguards

Including:
  • Written HIPAA policies.
  • Employee training.
  • Risk assessments.
  • Breach notification procedures.

Business Associate Agreements (BAAs)

You need signed BAAs with vendors that handle PHI, such as:
  • EHR platforms.
  • Telehealth software.
  • Cloud hosting providers.
  • Email providers.
  • Payment processors (if they process PHI).

Forms and Data Collection

Any intake forms, questionnaires, contact forms, or chat systems that collect patient information must be secure and HIPAA compliant.
Scroll to Top