HIPAA

Working with protected health information

Healthcare clients carry obligations that most software vendors quietly ignore. When we build for a practice, we build as a business associate under HIPAA and document how information is handled at every step.

Business associate agreements

Before any engagement that touches protected health information, we execute a business associate agreement defining permitted uses, safeguards, breach notification, and what happens to data when the relationship ends.

Minimum necessary

Systems are designed so that each user and each service reaches only the information required to do its job. Where a task can be accomplished with de-identified or aggregated data, that is what it receives.

AI services and PHI

Protected health information is never placed into consumer AI tools or into any service without an appropriate agreement in place. Where AI features are part of a healthcare system, we use providers that will sign a business associate agreement and that contractually do not train models on customer data.

Safeguards

Training and subcontractors

Personnel with access to protected health information complete HIPAA training. Any subcontractor with such access signs an equivalent agreement before work begins.

Questions and requests

For a copy of our business associate agreement template, a security questionnaire response, or a discussion of a specific compliance requirement, contact admin@localCLT.ai.

This page describes our practices and is not legal advice. Covered entities remain responsible for their own compliance programs.