What HepBuddy handles: patient name and contact details, the exercises and parameters your clinic assigns, patient-reported adherence, effort, and pain, message and delivery logs, and the name and contact details of the support person the patient picks.
What HepBuddy does not take: full medical records, diagnosis codes, patients' payment card data, or Social Security numbers.
Only for the service: HepBuddy uses patient data to run the service, to manage its own business, and to meet its legal duties. Nothing else.
Minimum necessary: HepBuddy asks for, uses, and shares only the minimum patient data needed for each purpose.
No sale, no marketing, no model training: HepBuddy never sells patient data, never uses it for marketing or fundraising, and never uses it to train a machine-learning model or build any product outside the service. HIPAA's de-identification rules still apply to de-identified data.
Messages to a support person: no patient data goes to a support person unless the patient has signed a written authorization that meets 45 C.F.R. § 164.508. HepBuddy enforces this in software. If the patient revokes it, HepBuddy stops within five business days.
Safeguards: HepBuddy follows the HIPAA Security Rule. That includes encryption of patient data in transit and at rest, a separate login for each user with role-based access, audit logs of access to patient data, and regular review of who has access.
Breach reporting: HepBuddy reports a breach to your clinic without unreasonable delay, and no later than 20 calendar days after discovering it. HIPAA allows up to 60. The report says, as far as known, which patients are affected, what happened and when, what data was involved, and what HepBuddy is doing about it.
Mitigation: HepBuddy limits any harm from a misuse of patient data as far as it practically can.
Same rules for every vendor: any vendor that stores, receives, or sends patient data for HepBuddy must first agree in writing to restrictions at least as strict as the ones HepBuddy accepts in this agreement.
HepBuddy stays responsible: HepBuddy remains liable to your clinic for how its vendors handle patient data.
Who they are: the current list, with what each vendor gets and when it signed a BAA, is at hepbuddy.com/vendors.html.
Exact wording of Section 3.8: “In accordance with 45 CFR 164.502(e)(1)(ii) and 164.308(b)(2), ensure that any Subcontractor that creates, receives, maintains, or transmits PHI on behalf of Business Associate agrees in writing to restrictions and conditions at least as restrictive as those that apply to Business Associate under this Agreement. Business Associate currently uses Subcontractors in the following categories: cloud infrastructure and data storage, transactional email delivery, and SMS message delivery. Business Associate maintains a current list of these Subcontractors and will provide it to Covered Entity on request. Business Associate remains liable to Covered Entity for its Subcontractors' handling of PHI.”
Access and amendment: HepBuddy provides records, or makes the changes you direct, within 10 business days of your written request. If a patient asks HepBuddy directly, HepBuddy sends the request to your clinic within five business days.
Accounting of disclosures: HepBuddy provides the information you need within 10 business days of a written request, and keeps it for six years.
Ending it: either side can end the agreement with 30 days' written notice. Either side can also end it for a material breach that is not fixed within 30 days of written notice.
Your data afterwards: your clinic can export its patient data at any time, and for 30 days after the agreement ends. After that, HepBuddy destroys the data within 60 days and confirms it in writing on request. The only exceptions are data the law requires HepBuddy to keep, or data that cannot practically be returned or destroyed. That data stays protected by this agreement.
HepBuddy's side: HepBuddy covers claims, penalties, breach notification, credit monitoring, and forensic costs caused by its own breach of this agreement or of HIPAA. That includes a breach by one of its vendors.
Your clinic's side: your clinic covers claims and penalties caused by its own breach, such as missing a required patient authorization or not closing a departed staff member's account.
Limit: HepBuddy's total liability is capped at three times the fees your clinic paid in the prior 12 months. The cap does not apply to gross negligence or willful misconduct.
Governing law: Washington State, except where federal law applies.