HIPAA Compliance & Security
HIPAA Compliance
For any customer data that involves their patients’ or clients’ personal information, that information isn’t covered by a general privacy policy alone — it falls under a separate HIPAA Business Associate Agreement, which takes precedence over the general policy whenever there’s a conflict. The overall privacy policy itself is also written specifically to satisfy the transparency obligations required under HIPAA.
Data Security & Protection
We apply a combination of administrative, technical, and physical safeguards to protect personal information from unauthorized access or misuse. Access to sensitive data is limited strictly to team members who need it to do their jobs, and everyone with that access is held to confidentiality obligations. We periodically review our internal security procedures to confirm they’re still effective, and we maintain a response plan in case of any suspected data breach. It’s worth noting, though, that no security setup is foolproof — if login credentials are ever shared with outside parties, protection of that data can no longer be fully guaranteed.
For payments, billing details are routed through a compliant third-party payment processor rather than stored directly on internal systems, reducing exposure of financial data.
We also use dedicated security cookies and monitoring tools that help detect unusual or potentially malicious activity, supporting broader efforts like account verification and fraud prevention.
As is standard for any online service, while commercially reasonable protective measures are used, no method of data transmission or storage over the internet can be guaranteed as 100% secure.