HIPAA and PHI Practices
Who this page is for
This page is a summary of how Health Hue Inc., operating as Health Hue Digital, handles protected health information when providing services to healthcare clients. It is written for our clients and for those evaluating us.
If you are a patient of a clinic we work with, your information is governed by that clinic's own privacy notice, not by this page.
This page is a summary and is not a contract. It is not legal advice, and it does not modify or replace the Business Associate Agreement between us, which is the operative document and governs in the event of any difference.
1. Our role
Where a client is a covered entity under the Health Insurance Portability and Accountability Act (HIPAA) and we create, receive, maintain, or transmit protected health information ("PHI") on that client's behalf, we act as a Business Associate under 45 CFR Parts 160 and 164.
We enter into a Business Associate Agreement with each such client before PHI is handled. The clinic decides what information is collected and why, and remains the party responsible to its patients for it.
For clients in Canada, a clinic may be a health information custodian under applicable provincial health-information legislation, and we act as its agent or information-processing service provider. PIPEDA applies to personal information more generally.
2. How we use PHI
We use PHI only to perform the services set out in your agreement, as your Business Associate Agreement permits, or as the law requires. Access is limited to the personnel who need it for that purpose.
We do not sell PHI. We do not use it for our own marketing or to build advertising audiences, and we do not use it to train artificial-intelligence models.
3. Safeguards
We maintain administrative, physical, and technical safeguards designed to protect PHI, consistent with the HIPAA Security Rule at 45 CFR §§164.308, 164.310, and 164.312. These cover access control, authentication, encryption, logging, personnel training and confidentiality obligations, vendor review, incident response, and secure disposal.
A current summary of our specific controls is available to clients and prospective clients on request, under a mutual non-disclosure agreement. No safeguard is absolute, and we do not represent that any system is immune from compromise.
4. Business Associate Agreements
We sign a Business Associate Agreement with every covered-entity client before handling PHI. We are glad to sign yours, or to provide ours.
We also hold Business Associate Agreements with the subprocessors that can access PHI on our behalf, as HIPAA requires. A vendor that has not signed one is not permitted to handle PHI.
5. Subprocessors
We use a small number of vendors to deliver the services. The categories that can involve PHI are:
- Clinic operating platform and CRM, including patient records, scheduling, and patient messaging, with call recording and transcription where enabled;
- AI voice and calling agent;
- Cloud infrastructure and the integration middleware that connects your systems through their APIs.
Each carries an executed Business Associate Agreement. Our website hosting and content-delivery layer is separate and holds no PHI.
The named subprocessor schedule, with each vendor's function and the status of its agreement, is provided in your Business Associate Agreement and to prospective clients on request.
Your own practice-management or electronic health record platform is your platform, not our subprocessor; you hold that agreement directly with the vendor. Where we build an integration, our role is limited to the connection between your systems, on your instructions.
6. Breach notification
If we discover a Breach of Unsecured PHI, as defined at 45 CFR §164.402, we notify the affected client in the manner and within the timeframe set out in the Business Associate Agreement between us and as applicable law requires, and we share the information available to us at the time.
We cooperate reasonably with your assessment and with any notification obligations you owe to individuals, regulators, or others, in both the United States and Canada.
7. Your data
We do not withhold protected health information over a billing dispute. Export timeframes are set out in your agreement. Only non-PHI data and materials may be withheld pending payment of undisputed amounts due.
At the end of an engagement we return or destroy PHI in accordance with our Business Associate Agreement.
8. Marketing, analytics, and advertising
Third-party tracking on healthcare websites is a recognised source of impermissible disclosure, and we treat it as a design constraint. We configure clinic websites and measurement so that patient information is not passed to advertising platforms, and we do not use PHI to build advertising audiences.
We do not use a patient's name, image, story, or testimonial in marketing, including our own case studies, without written authorisation.
9. Request our documentation
We would rather be checked than taken at our word. On request, and under a mutual non-disclosure agreement where appropriate, we provide:
- Our standard Business Associate Agreement;
- Our named subprocessor schedule, with agreement status;
- A current summary of our security controls;
- Our incident-response and breach-notification procedure;
- A certificate of insurance.
10. Contact us
Questions about this page, our Business Associate Agreement, or a suspected privacy incident:
- Email: info@healthhue.com
- Phone: +1 (647) 795-1440
- Mail: Health Hue Inc., 701 N Andrews Ave, Fort Lauderdale, FL 33311, United States
If you believe PHI may have been exposed, say so in the subject line and we will treat it as an incident immediately.
