Launch offer: Just Rs. 999/mo Rs. 6,999 — for the first 500 clinicians only.

HIPAA Compliance

Our commitment to protecting your patients' health information

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that sets national standards for protecting sensitive patient health information. HIPAA requires appropriate safeguards to protect the privacy and security of Protected Health Information (PHI).

As a cloud-based platform used by healthcare providers, LetPsyc acts as a Business Associateunder HIPAA. This means we handle PHI on behalf of Covered Entities (healthcare providers) and must comply with strict security and privacy requirements.

Business Associate Agreement (BAA)

All Professional and Enterprise subscribers automatically enter into a Business Associate Agreement (BAA) with LetPsyc. This legally binding contract ensures that:

  • We will appropriately safeguard PHI in our possession
  • We will report any security incidents or breaches
  • We will make PHI available to patients upon request
  • We will return or destroy PHI upon termination of services
  • We will ensure our subcontractors also comply with HIPAA
Technical Safeguards

We implement comprehensive technical measures to protect PHI in accordance with HIPAA Security Rule requirements:

Access Controls

  • Unique User Identification: Each user has a unique identifier and cannot share credentials
  • Role-Based Access Control (RBAC): Access to PHI is limited based on user roles and permissions
  • Multi-Factor Authentication (MFA): Required for all accounts to prevent unauthorized access
  • Automatic Logoff: Sessions automatically expire after 30 minutes of inactivity
  • Password Requirements: Enforced minimum complexity and rotation policies

Encryption

  • Data at Rest: AES-256 encryption for all stored PHI in databases and backups
  • Data in Transit: TLS 1.3 encryption for all data transmitted over networks
  • End-to-End Encryption: PHI is encrypted from point of entry to storage
  • Key Management: Secure key storage and rotation using AWS KMS

Audit Controls

  • Access Logging: All access to PHI is logged with timestamp, user ID, and action
  • Audit Trail: Immutable logs retained for 7 years per compliance requirements
  • Monitoring: Real-time monitoring of suspicious access patterns
  • Review Process: Regular audit log reviews by security team

Data Integrity

  • Hash Verification: Cryptographic hashing to detect unauthorized modifications
  • Version Control: All PHI changes are versioned and reversible
  • Data Validation: Input validation to prevent data corruption
  • Backup Integrity: Regular verification of backup data integrity

Transmission Security

  • Secure Protocols: HTTPS/TLS for all web traffic
  • API Security: Token-based authentication with short expiration times
  • Network Segmentation: PHI databases isolated in private subnets
  • VPN Access: Administrative access requires VPN connection
Administrative Safeguards

Security Management Process

  • Risk Analysis: Annual comprehensive risk assessments to identify vulnerabilities
  • Risk Management: Documented risk mitigation strategies and implementation
  • Sanction Policy: Disciplinary actions for policy violations
  • Information System Activity Review: Regular review of system logs and access reports

Workforce Security

  • Authorization/Supervision: Clear procedures for granting and revoking access rights
  • Workforce Clearance: Background checks for all employees with PHI access
  • Termination Procedures: Immediate access revocation upon employment termination
  • Need-to-Know Principle: Access limited to minimum necessary for job functions

Training and Awareness

  • Security Training: Mandatory HIPAA training for all workforce members
  • Annual Refresher: Yearly training updates on security policies
  • Incident Response Training: Regular drills for breach response procedures
  • Role-Specific Training: Additional training for roles with elevated PHI access

Contingency Planning

  • Data Backup Plan: Automated daily backups with 30-day retention
  • Disaster Recovery: Documented procedures for system restoration
  • Emergency Mode Operation: Procedures for continuing operations during emergencies
  • Testing and Revision: Semi-annual disaster recovery testing and plan updates

Business Associate Management

  • Written contracts with all subcontractors who access PHI
  • Regular compliance audits of business associates
  • Termination procedures for non-compliant vendors
  • Chain of trust documentation maintained
Physical Safeguards

Facility Access Controls

  • Data Center Security: SOC 2 Type II certified facilities with 24/7 monitoring
  • Biometric Access: Fingerprint and badge authentication for physical access
  • Video Surveillance: Continuous recording of all entry points
  • Visitor Logging: All visitors must sign in and be escorted
  • Environmental Controls: Fire suppression, UPS, and climate control systems

Workstation Security

  • Privacy screens on workstations with PHI access
  • Automatic screen lock after 5 minutes of inactivity
  • Encrypted hard drives on all company devices
  • Mobile device management (MDM) for remote access

Device and Media Controls

  • Secure disposal procedures for devices containing PHI
  • Data wiping using DOD 5220.22-M standard
  • Physical destruction of storage media when necessary
  • Certificate of destruction provided for all disposed media
Privacy Rule Compliance

In addition to Security Rule requirements, we comply with HIPAA Privacy Rule provisions:

Patient Rights Support

  • Right to Access: Tools for healthcare providers to provide patients with their PHI
  • Right to Amendment: Ability to correct or update inaccurate information
  • Right to Accounting: Audit logs support disclosure accounting requirements
  • Right to Restriction: System supports access restrictions per patient request

Minimum Necessary Standard

  • Role-based access ensures users only see PHI needed for their job function
  • Data segmentation limits exposure in case of unauthorized access
  • Query logging tracks who accessed what information and when

De-Identification Support

  • Tools for de-identifying data for research purposes
  • Compliant with Safe Harbor and Expert Determination methods
  • Limited data sets available with Data Use Agreements
Breach Notification Procedures

In the unlikely event of a security incident involving PHI, we have comprehensive breach notification procedures in place:

Incident Response Plan

  1. Detection: Security monitoring systems alert on anomalous activity (within minutes)
  2. Containment: Immediate isolation of affected systems (within 1 hour)
  3. Assessment: Evaluation of breach scope and impact (within 24 hours)
  4. Notification: Communication to affected parties as required by law
  5. Remediation: Implementation of corrective measures
  6. Documentation: Complete incident report and lessons learned

Notification Timeline

  • Healthcare Providers: Notified within 24 hours of breach discovery
  • Patients: You are responsible for patient notification (we provide support)
  • HHS: We report breaches affecting 500+ individuals to HHS within 60 days
  • Media: For breaches affecting 500+ individuals, media notification as required
Third-Party Compliance

All third-party service providers we use are carefully vetted for HIPAA compliance:

Amazon Web Services (AWS)

BAA signed • HIPAA-eligible services only • SOC 2 Type II certified

Google Cloud Platform

BAA signed • HIPAA-compliant infrastructure • ISO 27001 certified

Stripe

BAA signed • PCI DSS Level 1 compliant • No PHI processed

Sentry (Error Tracking)

BAA signed • PHI scrubbing before logging • Data encryption at rest

Compliance Certifications

HIPAA Compliant

Full compliance with Privacy & Security Rules

SOC 2 Type II

Annual security audits by independent CPA

ISO 27001

Information security management certified

HITRUST CSF

Healthcare information trust framework

Your Responsibilities as a Covered Entity

While we provide a HIPAA-compliant platform, you remain responsible for:

  • Conducting your own HIPAA risk assessments
  • Training your staff on HIPAA requirements
  • Obtaining patient consents and authorizations
  • Maintaining physical security of your devices
  • Notifying patients in the event of a breach
  • Ensuring compliance with state privacy laws
  • Using strong passwords and enabling MFA
  • Not sharing account credentials
Regular Compliance Audits

We conduct regular audits and assessments to ensure ongoing compliance:

  • Annual HIPAA Risk Assessment: Comprehensive evaluation of all security controls
  • Quarterly Vulnerability Scans: Automated scanning for security vulnerabilities
  • Semi-Annual Penetration Testing: Third-party ethical hacking assessments
  • Monthly Policy Reviews: Update policies to reflect regulatory changes
  • Continuous Monitoring: Real-time security event analysis
Contact Our Compliance Team

For questions about HIPAA compliance, to report a security concern, or to request compliance documentation:

Security Officer: security@letpsyc.com

Privacy Officer: privacy@letpsyc.com

Compliance Team: compliance@letpsyc.com

24/7 Security Hotline: +1 (555) 999-HIPAA

Mail: LetPsyc Compliance Team
123 Mental Health Ave, Suite 100
Los Angeles, CA 90210

Customer Support