One platform for websites, marketing & AI — built for clinics
See Plans →

Health Hue Digital

  • Operations overview→
    Calendar & SchedulingRun a full clinic day across every provider and room.Online BookingLet patients book themselves, 24/7.Express BookingBook a patient in under a minute.Unified InboxCalls, texts and web chats in one thread.Pipeline & OpportunitiesTurn inquiries into booked revenue.Patient RecordsOne complete record per patient.PaymentsTake payment anywhere, deposits included.AutomationsBuild it once, let it run.Reporting & AnalyticsKnow your numbers in real time.Memberships & PackagesTurn one-time visits into recurring revenue.
  • Marketing overview→
    CampaignsFill the schedule with multi-channel campaigns.Paid AdsMeta and Google ads that book patients.Social MediaShow up consistently across every channel.ReviewsFive-star proof, on autopilot.Email BuilderOn-brand emails in minutes.Creative LibraryOn-brand creative, ready to use.SEO & AI SearchGet found on Google and AI search.Affiliates & ReferralsTurn happy patients into promoters.
  • Websites
  • Industries
  • Hue AI
  • Pricing
Login Book Demo Call
Health Hue Digital
See Plans Operations Marketing WebsitesIndustries Hue AI Login
Book Demo
Skip to main content
Legal

HIPAA and PHI Practices

Last updated: August 6, 2026

Who this page is for

This page is a summary of how Health Hue Inc., operating as Health Hue Digital, handles protected health information when providing services to healthcare clients. It is written for our clients and for those evaluating us.

If you are a patient of a clinic we work with, your information is governed by that clinic's own privacy notice, not by this page.

This page is a summary and is not a contract. It is not legal advice, and it does not modify or replace the Business Associate Agreement between us, which is the operative document and governs in the event of any difference.

1. Our role

Where a client is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and we create, receive, maintain, or transmit protected health information ("PHI") on that client's behalf, we act as a Business Associate under 45 CFR Parts 160 and 164.

We enter into a Business Associate Agreement with each such client before PHI is handled. The clinic decides what information is collected and why, and remains the party responsible to its patients for it.

For clients in Canada, a clinic may be a health information custodian under applicable provincial health-information legislation, and we act as its agent or information-processing service provider. PIPEDA applies to personal information more generally.

2. How we use PHI

We use PHI only to perform the services set out in your agreement, as your Business Associate Agreement permits, or as the law requires. Access is limited to the personnel who need it for that purpose.

We do not sell PHI. We do not use it for our own marketing or to build advertising audiences, and we do not use it to train artificial-intelligence models.

3. Safeguards

We maintain administrative, physical, and technical safeguards designed to protect PHI, consistent with the HIPAA Security Rule at 45 CFR §§164.308, 164.310, and 164.312. These cover access control, authentication, encryption, logging, personnel training and confidentiality obligations, vendor review, incident response, and secure disposal.

A current summary of our specific controls is available to clients and prospective clients on request, under a mutual non-disclosure agreement. No safeguard is absolute, and we do not represent that any system is immune from compromise.

4. Business Associate Agreements

We sign a Business Associate Agreement with every covered-entity client before handling PHI. We are glad to sign yours, or to provide ours.

We also hold Business Associate Agreements with the subprocessors that can access PHI on our behalf, as HIPAA requires. A vendor that has not signed one is not permitted to handle PHI.

5. Subprocessors

We use a small number of vendors to deliver the services. The categories that can involve PHI are:

  • Clinic operating platform and CRM, including patient records, scheduling, and patient messaging, with call recording and transcription where enabled;
  • AI voice and calling agent;
  • Cloud infrastructure and the integration middleware that connects your systems through their APIs.

Each carries an executed Business Associate Agreement. Our website hosting and content-delivery layer is separate and holds no PHI.

The named subprocessor schedule, with each vendor's function and the status of its agreement, is provided in your Business Associate Agreement and to prospective clients on request.

Your own practice-management or electronic health record platform is your platform, not our subprocessor; you hold that agreement directly with the vendor. Where we build an integration, our role is limited to the connection between your systems, on your instructions.

6. Breach notification

If we discover a Breach of Unsecured PHI, as defined at 45 CFR §164.402, we notify the affected client in the manner and within the timeframe set out in the Business Associate Agreement between us and as applicable law requires, and we share the information available to us at the time.

We cooperate reasonably with your assessment and with any notification obligations you owe to individuals, regulators, or others, in both the United States and Canada.

7. Your data

We do not withhold protected health information over a billing dispute. Export timeframes are set out in your agreement. Only non-PHI data and materials may be withheld pending payment of undisputed amounts due.

At the end of an engagement we return or destroy PHI in accordance with our Business Associate Agreement.

8. Marketing, analytics, and advertising

Third-party tracking on healthcare websites is a recognised source of impermissible disclosure, and we treat it as a design constraint. We configure clinic websites and measurement so that patient information is not passed to advertising platforms, and we do not use PHI to build advertising audiences.

We do not use a patient's name, image, story, or testimonial in marketing, including our own case studies, without written authorisation.

9. Request our documentation

We would rather be checked than taken at our word. On request, and under a mutual non-disclosure agreement where appropriate, we provide:

  • Our standard Business Associate Agreement;
  • Our named subprocessor schedule, with agreement status;
  • A current summary of our security controls;
  • Our incident-response and breach-notification procedure;
  • A certificate of insurance.

10. Contact us

Questions about this page, our Business Associate Agreement, or a suspected privacy incident:

  • Email: info@healthhue.com
  • Phone: +1 (647) 795-1440
  • Mail: Health Hue Inc., 701 N Andrews Ave, Fort Lauderdale, FL 33311, United States

If you believe PHI may have been exposed, say so in the subject line and we will treat it as an incident immediately.

Health Hue Digital

The growth platform for medical aesthetics. GEO and AI search, paid media, creative, and the Health Hue Hub in one stack.

701 N Andrews Ave, Fort Lauderdale, FL 33311, United States

Website

Clinic Websites Modern Website Online Booking Treatment Add-Ons Built for AI Search

Operations

Operations Hub Booking & Calendar Unified Inbox Payments & POS Memberships CRM & Reporting

Marketing

Marketing Hub Paid Ads Email & SMS Social Content Reviews & Reputation Attribution

Hue AI

Hue AI Overview AI Receptionist Lead Qualification Conversational Booking Content Generation Review Replies

Company

AboutPricingFree ToolsLearnCareersContactBook DemoLogin
© 2026 Health Hue Digital. All rights reserved. Privacy Policy Terms & Conditions Terms of Service HIPAA & PHI Accessibility
Download on the App Store