Logo

HIPAA Compliance Statement

AnswerClinic Commitment to Security and Privacy

1. Overview

At AnswerClinic, we are committed to protecting the privacy and security of Protected Health Information (PHI). We understand that as a healthcare technology provider, our robust adherence to the Health Insurance Portability and Accountability Act of 1996 ("HIPAA") and the HITECH Act is essential for our users ("Covered Entities").

This statement outlines the administrative, physical, and technical safeguards we have implemented to ensure the confidentiality, integrity, and availability of PHI.

2. Business Associate Agreement (BAA)

AnswerClinic operates as a Business Associate to our healthcare provider clients. We are fully prepared to execute a Business Associate Agreement (BAA) with your medical practice. This agreement legally binds us to protect your patients' data in accordance with federal regulations.

3. Technical Safeguards

We employ industry-standard encryption and security protocols to protect data:

  • Encryption in Transit: All data transmitted between your device and our servers is encrypted using Transport Layer Security (TLS) 1.2 or higher.
  • Encryption at Rest: Sensitive medical data and files stored in our databases and file systems (via Google Cloud Firestore and AWS S3) are encrypted using advanced encryption standards (AES-256).
  • Access Control: We implement strict Role-Based Access Control (RBAC). Only authorized personnel with a legitimate business need can access the backend infrastructure.
  • Secure Communication: Teleconsultations and voice data processed via Twilio are secured and compliant with HIPAA transmission standards.

4. Physical and Infrastructure Safeguards

AnswerClinic does not host its own physical servers. We leverage the world-class, HIPAA-compliant infrastructure of trusted third-party providers:

  • Amazon Web Services (AWS)
  • Google Cloud Platform (Firebase)
  • Twilio

These providers maintain ISO 27001 certification and strictly controlled physical data centers with 24/7 surveillance and biometric access controls.

5. Administrative Safeguards

  • Staff Training: All AnswerClinic employees and contractors undergo privacy and security training regarding the handling of PHI.
  • Minimum Necessary Standard: We request and use only the minimum amount of PHI necessary to perform our services and improve the App.
  • Audit Logs: We maintain logs of system access and activity to detect and investigate any potential security anomalies.

6. Data Breach Notification

In the unlikely event of a data breach compromising unsecured PHI, AnswerClinic has a defined incident response plan. We will notify the affected Covered Entity (the Provider) without unreasonable delay and in no case later than 60 days following the discovery of the breach, as required by law.

7. Contact Us

For questions regarding our HIPAA compliance program or to request a signed BAA for your records, please contact our Compliance Officer:

Name: Dr. Peter Hanna

Email: info@answerclinic.com

Address: 8950 SW 74th CT Suite 1408, Miami FL 33156