Is Recovery Record for Clinicians HIPAA compliant?
Yes
Recovery Record is, indeed, compliant with the HITECH Act and HIPAA legislation.
Some key components of this are; all data is encrypted on the device, in transit, and at rest in our backend systems, data is hosted in a HIPAA secure hosting environment, we do not transmit any protected health information via insecure channels such as email. We also have protocols in place for how to respond in the unlikely event (given the above security infrastructure) in the instance that there is a security breach. Finally, we uphold provisions regarding how we use the data (only to improve the the technology and provide the service, and occasionally at aggregate, de-identified level for research purposes with research institutions, on the patient’s permission).
We also institute a Business Associate Agreement which any provider with an NPI can request, which provides legal assurance that we will do everything we say we will, that we will meet our legal obligations for protection of patient data.