Legal & Compliance
Every legal and compliance page requires review by an attorney licensed in South Carolina before publication. Several describe obligations that must genuinely be in place rather than merely described. This is drafted content, not executed policy, and it is not legal advice.
How protected health information is handled under HIPAA and the HIPAA Security Rule.
Business Associate status
This firm is a Business Associate as defined under 45 CFR 160.103 when performing services that involve access to protected health information (PHI). A Business Associate Agreement (BAA) is executed before any PHI is accessed, meeting the requirements of 45 CFR 164.502(e) and 164.504(e).
Administrative, physical, and technical safeguards
The HIPAA Security Rule (45 CFR Part 164, Subpart C) requires administrative, physical, and technical safeguards. This firm maintains:
- Encryption of PHI in transit and at rest
- Multi-factor authentication on all systems accessing PHI
- Access controls limiting PHI to authorized personnel
- Audit logging of who accessed what and when
- Annual written risk assessment
- Workforce training on HIPAA and security
- Secure disposal of PHI when no longer required
Minimum necessary
Access to PHI is limited to the minimum necessary to accomplish the intended purpose of the use or disclosure.
Breach notification
In the event of a breach of unsecured PHI, this firm provides notification to the covered entity without unreasonable delay and no later than 60 days from discovery, as required by 45 CFR 164.410. The notification includes the identification of each individual affected, to the extent possible.
Subcontractor flow-down
Every subcontractor or vendor that touches PHI executes a Business Associate Agreement with this firm, creating flow-down of HIPAA obligations. This includes cloud storage providers, backup providers, and any other vendor with PHI access.
Direct liability
Since the HITECH Act of 2009 and the 2013 Omnibus Rule, Business Associates are directly liable for compliance with the Security Rule and for breach notification. This firm maintains insurance limits of $2M professional liability, $2M general liability, and $2M cyber liability.
Secure channels only
PHI is exchanged only through secured channels a secure client portal with encryption in transit and at rest, multi-factor authentication, and audit logging. PHI is never exchanged through email or through this website's forms.