{"id":7091,"date":"2024-01-17T15:49:25","date_gmt":"2024-01-17T15:49:25","guid":{"rendered":"https:\/\/www.process.st\/help\/docs\/hipaa-compliance\/"},"modified":"2026-05-15T09:01:38","modified_gmt":"2026-05-15T09:01:38","slug":"hipaa-compliance","status":"publish","type":"ht_kb","link":"https:\/\/www.process.st\/help\/docs\/hipaa-compliance\/","title":{"rendered":"HIPAA Compliance"},"content":{"rendered":"<p><b>If you&#8217;re interested in HIPAA compliance, please reach out to your account executive or <a href=\"mailto:support@process.st\">contact support<\/a>.<\/b><\/p>\n<div class=\"guide-content\" data-swiftype-name=\"body\" data-swiftype-type=\"text\">\n<p>The Health Insurance Portability and Accountability Act (HIPAA) is designed to help protect people\u2019s healthcare data. Organizations such as hospitals, doctors&#8217; offices, health plans, or companies dealing with protected health information (PHI) are required to be HIPAA-compliant. This may also extend to companies that work with these businesses and come into contact with PHI on their behalf.<\/p>\n<p><span class=\"wysiwyg-color-black\">Here are some key terms you should know:<\/span><\/p>\n<ul>\n<li><span class=\"wysiwyg-color-black\"><strong>Protected Health Information (PHI)<\/strong><\/span><\/li>\n<\/ul>\n<p><span class=\"wysiwyg-color-black\">PHI is healthcare data relating to a patient and collected by a healthcare provider, employer, or plan. It includes names, social security numbers, phone numbers, medical history, current medical condition, test results, and more. PHI is the content that HIPAA aims to protect and keep private.<\/span><\/p>\n<ul>\n<li><span class=\"wysiwyg-color-black\"><strong>Covered Entity<\/strong><\/span><\/li>\n<\/ul>\n<p><span class=\"wysiwyg-color-black\">A covered entity is anyone who provides treatment, payment, and operations in healthcare. Examples include doctors, hospitals, pharmacies, insurance companies, and more. These covered entities are responsible for the privacy and security of health information.<\/span><\/p>\n<ul>\n<li><span class=\"wysiwyg-color-black\"><strong>Business Associate<\/strong><\/span><\/li>\n<\/ul>\n<p><span class=\"wysiwyg-color-black\">A business associate is anyone who has access to a patient&#8217;s information whether it is directly, indirectly, physically, or virtually. A business associate does not work under the covered entity\u2019s workforce but instead performs some type of service on their behalf (i.e. a lawyer, a phone company, etc.). A business associate is subject to HIPAA rules.<\/span><\/p>\n<ul>\n<li><span class=\"wysiwyg-color-black\"><strong>Business Associate Agreement (BAA)<\/strong><\/span><\/li>\n<\/ul>\n<p><span class=\"wysiwyg-color-black\">A BAA is a contractual assurance from the business associate to the covered entity that they follow HIPAA&#8217;s requirements. This agreement must be in place before the transfer of PHI from the covered entity to the business associate.\u00a0<\/span><\/p>\n<h2 id=\"01GQVEHKA1M9FCXS2DNS0S1R6Y\"><span class=\"wysiwyg-font-size-large\"><span class=\"wysiwyg-color-black\">Is Process Street HIPAA compliant?<\/span><\/span><\/h2>\n<p><span class=\"wysiwyg-color-black\">HIPAA is available on Process Street on our <strong>Enterprise<\/strong>\u00a0plan. Please note that if you are on this plan and later downgrade to another plan, you will no longer be covered under the HIPAA compliance program anymore.<\/span><\/p>\n<h2 id=\"01GQVEHKA1E1PP2MDMM08YA7KS\"><span class=\"wysiwyg-color-black wysiwyg-font-size-large\">How do I enable HIPAA compliance?<\/span><\/h2>\n<p>You do not need to do anything to enable HIPAA compliance, we will do this for you once an Enterprise contract and BAA are in place.<\/p>\n<h2>What happens to Process Street when HIPAA compliance is enabled?<\/h2>\n<p>When HIPAA compliance is enabled, the following will happen:<\/p>\n<ul>\n<li><a href=\"https:\/\/www.process.st\/help\/docs\/enhanced-file-security\/\">Enhanced File Security<\/a> will be enabled.<\/li>\n<li>Form field values will be redacted in <a href=\"https:\/\/www.process.st\/help\/docs\/approvals\/\">Approvals<\/a> emails.<\/li>\n<\/ul>\n<h2>Additional product use considerations<\/h2>\n<ul>\n<li>PHI storage should be limited to form fields, comments and attachments.<\/li>\n<li>You should not <a href=\"https:\/\/www.process.st\/help\/docs\/comments\/\">@mention<\/a> someone in a comment that contains PHI.<\/li>\n<li>You should not use variables containing PHI in <a href=\"https:\/\/www.process.st\/help\/docs\/getting-started-using-the-send-email-widget\/\">the Send Email form field<\/a>.<\/li>\n<li>You should not use variables containing PHI in <a href=\"https:\/\/www.process.st\/help\/docs\/ai-tasks\/\">AI Tasks<\/a>.<\/li>\n<li>Process Street is not an EHR (Electronic Health Record). Process Street does not maintain the designated record set and should not be the system of record for health information. Customers may not create Process Street accounts in their domain for their patients, patient family members, plan members, or any other external parties to communicate.<\/li>\n<li>When contacting Process Street support, you should not provide PHI in any support tickets. Please do not share PHI when on calls with Process Street representatives.<\/li>\n<\/ul>\n<h2>Additional data security options<\/h2>\n<h3><span class=\"wysiwyg-color-black\">1.\u00a0Strengthen authentication<\/span><\/h3>\n<p><span class=\"wysiwyg-color-black\">We recommend using <a href=\"https:\/\/www.process.st\/help\/docs\/single-sign-on-sso-at-process-street\/\">SAML Single Sign-On (SSO)<\/a> to add a layer of protection to your Process Street account.<\/span><\/p>\n<h3><span class=\"wysiwyg-color-black\">2. Conduct regular access reviews<\/span><\/h3>\n<p>To ensure that any sensitive data in your Process Street account can only be accessed by appropriate people, we recommend that you frequently review the list of your members.<\/p>\n<\/div>\n<p>You can use <a href=\"https:\/\/www.process.st\/help\/docs\/scim-okta\/\">SCIM<\/a> to automatically manage the users in your organization.<\/p>\n<h3>3. Evaluate third-party apps<\/h3>\n<p>Our third-party integrations allow you to seamlessly connect Process Street to external platforms. While these third-party apps can be great complements to your account, it\u2019s important to remember that they\u2019re not part of our included services. If you want to keep the HIPAA compliance, you must ensure that any third-party app or service you use will also be HIPAA compliant.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>If you&#8217;re interested in HIPAA compliance, please reach out to your account executive or contact support. The Health Insurance Portability and Accountability Act (HIPAA) is designed to help protect people\u2019s healthcare data. Organizations such as hospitals, doctors&#8217; offices, health plans, or companies dealing with protected health information (PHI) are required to be HIPAA-compliant. This may [&hellip;]<\/p>\n","protected":false},"author":2,"template":"","meta":{"_acf_changed":false,"available_plan":"Enterprise","available_product":"Settings","footnotes":""},"ht_kb_category":[239],"ht_kb_tag":[],"class_list":["post-7091","ht_kb","type-ht_kb","status-publish","hentry","ht_kb_category-security"],"acf":[],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/7091","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb"}],"about":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/types\/ht_kb"}],"author":[{"embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/users\/2"}],"version-history":[{"count":2,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/7091\/revisions"}],"predecessor-version":[{"id":9972,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb\/7091\/revisions\/9972"}],"wp:attachment":[{"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/media?parent=7091"}],"wp:term":[{"taxonomy":"ht_kb_category","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_category?post=7091"},{"taxonomy":"ht_kb_tag","embeddable":true,"href":"https:\/\/www.process.st\/help\/wp-json\/wp\/v2\/ht_kb_tag?post=7091"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}