HIPAA Compliance
Our commitment to protecting your patients' health information
HIPAA-Compliant Platform
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that sets national standards for protecting sensitive patient health information. HIPAA requires appropriate safeguards to protect the privacy and security of Protected Health Information (PHI).
As a cloud-based platform used by healthcare providers, LetPsyc acts as a Business Associateunder HIPAA. This means we handle PHI on behalf of Covered Entities (healthcare providers) and must comply with strict security and privacy requirements.
All Professional and Enterprise subscribers automatically enter into a Business Associate Agreement (BAA) with LetPsyc. This legally binding contract ensures that:
- We will appropriately safeguard PHI in our possession
- We will report any security incidents or breaches
- We will make PHI available to patients upon request
- We will return or destroy PHI upon termination of services
- We will ensure our subcontractors also comply with HIPAA
We implement comprehensive technical measures to protect PHI in accordance with HIPAA Security Rule requirements:
Access Controls
- Unique User Identification: Each user has a unique identifier and cannot share credentials
- Role-Based Access Control (RBAC): Access to PHI is limited based on user roles and permissions
- Multi-Factor Authentication (MFA): Required for all accounts to prevent unauthorized access
- Automatic Logoff: Sessions automatically expire after 30 minutes of inactivity
- Password Requirements: Enforced minimum complexity and rotation policies
Encryption
- Data at Rest: AES-256 encryption for all stored PHI in databases and backups
- Data in Transit: TLS 1.3 encryption for all data transmitted over networks
- End-to-End Encryption: PHI is encrypted from point of entry to storage
- Key Management: Secure key storage and rotation using AWS KMS
Audit Controls
- Access Logging: All access to PHI is logged with timestamp, user ID, and action
- Audit Trail: Immutable logs retained for 7 years per compliance requirements
- Monitoring: Real-time monitoring of suspicious access patterns
- Review Process: Regular audit log reviews by security team
Data Integrity
- Hash Verification: Cryptographic hashing to detect unauthorized modifications
- Version Control: All PHI changes are versioned and reversible
- Data Validation: Input validation to prevent data corruption
- Backup Integrity: Regular verification of backup data integrity
Transmission Security
- Secure Protocols: HTTPS/TLS for all web traffic
- API Security: Token-based authentication with short expiration times
- Network Segmentation: PHI databases isolated in private subnets
- VPN Access: Administrative access requires VPN connection
Security Management Process
- Risk Analysis: Annual comprehensive risk assessments to identify vulnerabilities
- Risk Management: Documented risk mitigation strategies and implementation
- Sanction Policy: Disciplinary actions for policy violations
- Information System Activity Review: Regular review of system logs and access reports
Workforce Security
- Authorization/Supervision: Clear procedures for granting and revoking access rights
- Workforce Clearance: Background checks for all employees with PHI access
- Termination Procedures: Immediate access revocation upon employment termination
- Need-to-Know Principle: Access limited to minimum necessary for job functions
Training and Awareness
- Security Training: Mandatory HIPAA training for all workforce members
- Annual Refresher: Yearly training updates on security policies
- Incident Response Training: Regular drills for breach response procedures
- Role-Specific Training: Additional training for roles with elevated PHI access
Contingency Planning
- Data Backup Plan: Automated daily backups with 30-day retention
- Disaster Recovery: Documented procedures for system restoration
- Emergency Mode Operation: Procedures for continuing operations during emergencies
- Testing and Revision: Semi-annual disaster recovery testing and plan updates
Business Associate Management
- Written contracts with all subcontractors who access PHI
- Regular compliance audits of business associates
- Termination procedures for non-compliant vendors
- Chain of trust documentation maintained
Facility Access Controls
- Data Center Security: SOC 2 Type II certified facilities with 24/7 monitoring
- Biometric Access: Fingerprint and badge authentication for physical access
- Video Surveillance: Continuous recording of all entry points
- Visitor Logging: All visitors must sign in and be escorted
- Environmental Controls: Fire suppression, UPS, and climate control systems
Workstation Security
- Privacy screens on workstations with PHI access
- Automatic screen lock after 5 minutes of inactivity
- Encrypted hard drives on all company devices
- Mobile device management (MDM) for remote access
Device and Media Controls
- Secure disposal procedures for devices containing PHI
- Data wiping using DOD 5220.22-M standard
- Physical destruction of storage media when necessary
- Certificate of destruction provided for all disposed media
In addition to Security Rule requirements, we comply with HIPAA Privacy Rule provisions:
Patient Rights Support
- Right to Access: Tools for healthcare providers to provide patients with their PHI
- Right to Amendment: Ability to correct or update inaccurate information
- Right to Accounting: Audit logs support disclosure accounting requirements
- Right to Restriction: System supports access restrictions per patient request
Minimum Necessary Standard
- Role-based access ensures users only see PHI needed for their job function
- Data segmentation limits exposure in case of unauthorized access
- Query logging tracks who accessed what information and when
De-Identification Support
- Tools for de-identifying data for research purposes
- Compliant with Safe Harbor and Expert Determination methods
- Limited data sets available with Data Use Agreements
In the unlikely event of a security incident involving PHI, we have comprehensive breach notification procedures in place:
Incident Response Plan
- Detection: Security monitoring systems alert on anomalous activity (within minutes)
- Containment: Immediate isolation of affected systems (within 1 hour)
- Assessment: Evaluation of breach scope and impact (within 24 hours)
- Notification: Communication to affected parties as required by law
- Remediation: Implementation of corrective measures
- Documentation: Complete incident report and lessons learned
Notification Timeline
- Healthcare Providers: Notified within 24 hours of breach discovery
- Patients: You are responsible for patient notification (we provide support)
- HHS: We report breaches affecting 500+ individuals to HHS within 60 days
- Media: For breaches affecting 500+ individuals, media notification as required
Breach History
All third-party service providers we use are carefully vetted for HIPAA compliance:
Amazon Web Services (AWS)
BAA signed • HIPAA-eligible services only • SOC 2 Type II certified
Google Cloud Platform
BAA signed • HIPAA-compliant infrastructure • ISO 27001 certified
Stripe
BAA signed • PCI DSS Level 1 compliant • No PHI processed
Sentry (Error Tracking)
BAA signed • PHI scrubbing before logging • Data encryption at rest
HIPAA Compliant
Full compliance with Privacy & Security Rules
SOC 2 Type II
Annual security audits by independent CPA
ISO 27001
Information security management certified
HITRUST CSF
Healthcare information trust framework
While we provide a HIPAA-compliant platform, you remain responsible for:
- Conducting your own HIPAA risk assessments
- Training your staff on HIPAA requirements
- Obtaining patient consents and authorizations
- Maintaining physical security of your devices
- Notifying patients in the event of a breach
- Ensuring compliance with state privacy laws
- Using strong passwords and enabling MFA
- Not sharing account credentials
We conduct regular audits and assessments to ensure ongoing compliance:
- Annual HIPAA Risk Assessment: Comprehensive evaluation of all security controls
- Quarterly Vulnerability Scans: Automated scanning for security vulnerabilities
- Semi-Annual Penetration Testing: Third-party ethical hacking assessments
- Monthly Policy Reviews: Update policies to reflect regulatory changes
- Continuous Monitoring: Real-time security event analysis
For questions about HIPAA compliance, to report a security concern, or to request compliance documentation:
Security Officer: security@letpsyc.com
Privacy Officer: privacy@letpsyc.com
Compliance Team: compliance@letpsyc.com
24/7 Security Hotline: +1 (555) 999-HIPAA
Mail: LetPsyc Compliance Team
123 Mental Health Ave, Suite 100
Los Angeles, CA 90210
