HIPAACompliance

HIPAA Compliance Policy

Last Updated: February 27, 2026

Overview

PrivatePayCare is committed to protecting the privacy and security of Protected Health Information (PHI) in accordance with the Health Insurance Portability and Accountability Act (HIPAA).

1. PHI Definition

Protected Health Information includes any health data that can be linked to an individual:

  • Medical history and diagnoses
  • Medications and allergies
  • Treatment plans
  • Functional limitations

2. PHI Access & Authorization

  • PHI is only shared with caregivers assigned to the client
  • Written authorization required before sharing with third parties
  • Access logs are maintained and audited

3. Data Security Safeguards

  • Encryption in transit (SSL/TLS)
  • Encryption at rest (AES-256)
  • Regular security audits
  • Secure access controls

4. Breach Notification

In the event of a PHI breach, affected individuals will be notified within 60 days as required by law.

5. Business Associate Agreements

All third parties with access to PHI must sign a Business Associate Agreement (BAA).

6. User Responsibilities

Users must:

  • Keep login credentials confidential
  • Report suspected breaches immediately
  • Comply with our caregiver code of conduct

7. Contact Information

For HIPAA questions or to report a breach: privacy@privateplaycare.com