We maintain administrative, physical, and technical safeguards designed to protect the confidentiality, integrity, and availability of your PHI in accordance with applicable federal regulations. Access to PHI is limited to authorized personnel who require it to perform their duties.
Business Associate Agreements (BAAs). Where any vendor, service provider, or partner creates, receives, maintains, or transmits protected health information on our behalf, a written Business Associate Agreement consistent with 45 CFR §164.504(e) must be in place before any PHI is shared. BAAs must be executed and current for every covered vendor — including the telehealth evaluation platform (Qualiphy), pharmacy fulfillment partners, payment processors handling protected data, hosting providers, and any analytics or communication tools that may come into contact with PHI. No PHI is transmitted to a vendor without a signed, current BAA.
Minimum necessary. We limit uses, disclosures, and requests of PHI to the minimum necessary to accomplish the intended purpose, except for treatment purposes or as otherwise required or permitted by law.
Preview note: This prototype website does not collect, transmit, or store protected health information through ordinary marketing forms. No medical intake, health history, or prescription data is processed by this website itself. All clinical evaluation and medical intake is handled through the separate, HIPAA-covered Qualiphy workflow.