Skip to main content
Resiliens
Security & Compliance

HIPAA Compliance

How We Protect Your Health Information

End-to-End Encryption

All data encrypted in transit (TLS 1.3) and at rest (AES-256).

Secure Infrastructure

HIPAA-compliant cloud with SOC 2 Type II certification.

Access Controls

Role-based access ensures only authorized personnel reach PHI.

Our Commitment to HIPAA Compliance

Resiliens is fully committed to complying with the Health Insurance Portability and Accountability Act (HIPAA) and its implementing regulations. We maintain comprehensive administrative, physical, and technical safeguards to protect the confidentiality, integrity, and availability of all protected health information (PHI) entrusted to us. Our compliance program is regularly reviewed and updated to reflect changes in regulations and industry best practices.

Business Associate Agreement (BAA)

As a Business Associate under HIPAA, Resiliens enters into Business Associate Agreements with all Covered Entities and their agents. Our BAA covers the following key provisions:

  • Permitted uses and disclosures of PHI
  • Obligations to safeguard PHI
  • Breach notification procedures
  • Subcontractor compliance requirements
  • Individual rights to access and amend PHI
  • Return or destruction of PHI upon termination
  • Accounting of disclosures
  • Compliance with the HIPAA Security Rule

Administrative Safeguards

Our administrative safeguards form the foundation of our HIPAA compliance program.

Security Management Process

Comprehensive risk analysis and management program to identify and mitigate potential threats to PHI.

Workforce Security

Background checks, role-based access, and regular security training for all personnel with access to PHI.

Access Management

Strict policies governing the authorization, establishment, and modification of access to PHI.

Security Awareness Training

Regular training programs to ensure all workforce members understand their responsibilities regarding PHI security.

Security Incident Procedures

Documented procedures for identifying, responding to, mitigating, and reporting security incidents.

Contingency Planning

Data backup, disaster recovery, and emergency mode operation plans to ensure PHI availability.

Breach Notification

  • Detection and investigation within 24 hours of discovery
  • Notification to affected Covered Entities without unreasonable delay
  • Notification to individuals within 60 days of discovery when required
  • Documentation and reporting to the HHS Office for Civil Rights
  • Corrective action plans to prevent future incidents

Subcontractor Management

We hold our subcontractors to the same high standards of HIPAA compliance:

  • BAAs required with all subcontractors that access PHI
  • Regular compliance assessments and audits
  • Security requirements embedded in all contracts
  • Ongoing monitoring and incident response coordination

Individual Rights

We support the rights of individuals regarding their PHI:

  • Right to access and obtain a copy of their PHI
  • Right to request amendments to their PHI
  • Right to an accounting of disclosures
  • Right to request restrictions on certain uses and disclosures
  • Right to receive confidential communications
  • Right to file a complaint with the HHS Office for Civil Rights

Request a Business Associate Agreement

If you are a Covered Entity or healthcare organization looking to partner with Resiliens, we are ready to execute a Business Associate Agreement.

Or email us directly at info@resiliens.com

Related Policies

Review our other legal documents for more information about how we protect your data.