Notice of Privacy Practices
Required for covered healthcare entities. It explains:
- How Protected Health Information (PHI) is used and disclosed.
- Patient rights to access and amend records.
- How patients can file complaints.
Technical Safeguards
HIPAA requires:
- SSL encryption (HTTPS).
- Secure hosting.
- Access controls and passwords.
- Audit logs.
- Encrypted storage and transmission of PHI.
- Automatic logoff and authentication procedures.
Administrative Safeguards
Including:
- Written HIPAA policies.
- Employee training.
- Risk assessments.
- Breach notification procedures.
Business Associate Agreements (BAAs)
You need signed BAAs with vendors that handle PHI, such as:
- EHR platforms.
- Telehealth software.
- Cloud hosting providers.
- Email providers.
- Payment processors (if they process PHI).
Forms and Data Collection
Any intake forms, questionnaires, contact forms, or chat systems that collect patient information must be secure and HIPAA compliant.