HIPAA Compliance
CrownDesk is designed from the ground up to meet HIPAA requirements, ensuring your patient data remains secure and compliant.
HIPAA Compliant
Certified Business Associate
BAA Included
Automatic Agreement
PHI Protected
End-to-End Security
What is HIPAA?
The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that requires the protection and confidential handling of protected health information (PHI). HIPAA applies to covered entities and their business associates.
Key HIPAA Requirements
- • Privacy Rule: Protects individual health information held by covered entities
- • Security Rule: Sets standards for protecting electronic PHI (ePHI)
- • Breach Notification Rule: Requires notification of PHI breaches
- • Omnibus Rule: Strengthens patient privacy protections
Who Must Comply?
Covered Entities
- • Healthcare providers
- • Health plans
- • Healthcare clearinghouses
Business Associates
- • Technology vendors
- • Billing companies
- • Cloud service providers
CrownDesk HIPAA Compliance
Business Associate Agreement (BAA)
CrownDesk signs a Business Associate Agreement with all healthcare customers automatically upon subscription. This agreement outlines our responsibilities for protecting PHI and our compliance with HIPAA requirements.
PHI Handling Safeguards
Administrative Safeguards
Security officer designation, workforce training, access management
Physical Safeguards
Facility access controls, workstation security, device/media controls
Technical Safeguards
Access control, audit controls, integrity, transmission security
Minimum Necessary Standard
CrownDesk implements role-based access controls ensuring users only access the minimum PHI necessary to perform their job functions. This includes granular permissions and audit trails for all data access.
Technical Security Measures
Encryption Requirements
Data in Transit
- • TLS 1.3 encryption for all communications
- • Perfect Forward Secrecy implementation
- • Certificate pinning and validation
Data at Rest
- • AES-256 encryption for all stored PHI
- • Database-level encryption
- • Encrypted backup storage
Access Controls
- • Unique user identification for each person accessing PHI
- • Role-based access control with principle of least privilege
- • Multi-factor authentication required for all users
- • Automatic logoff after period of inactivity
- • Encryption and decryption controls
Audit Controls
- • Comprehensive audit logs for all PHI access
- • Immutable audit trail storage
- • Real-time monitoring and alerting
- • Regular audit log review and analysis
Your HIPAA Responsibilities
As a Covered Entity
- • Ensure all workforce members are trained on HIPAA requirements
- • Implement and maintain required administrative, physical, and technical safeguards
- • Designate a HIPAA Security Officer and Privacy Officer
- • Conduct periodic security assessments
- • Have an incident response plan for potential breaches
Using CrownDesk Compliantly
- • Use strong, unique passwords and enable multi-factor authentication
- • Log out of the system when not in use
- • Do not share login credentials with other users
- • Report any suspected security incidents immediately
- • Only access PHI when necessary for your job duties
Patient Rights
- • Right to access their PHI
- • Right to request amendments to their PHI
- • Right to an accounting of PHI disclosures
- • Right to request restrictions on use/disclosure
- • Right to request confidential communications
Breach Response
What Constitutes a Breach?
A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI.
CrownDesk Breach Response
- • Immediate containment and assessment of the incident
- • Investigation to determine scope and cause
- • Notification to affected customers within 24 hours
- • Assistance with breach notification requirements
- • Implementation of corrective measures
Your Breach Notification Requirements
- • Notify individuals within 60 days
- • Notify HHS within 60 days
- • Notify media if breach affects 500+ individuals
- • Maintain documentation of all breaches
Compliance Resources
Training and Education
- • HIPAA compliance training for your staff
- • Regular security awareness updates
- • Best practices documentation
- • Compliance webinars and workshops
Documentation
- • Business Associate Agreement template
- • Security policies and procedures
- • Risk assessment templates
- • Incident response planning guides
Support
Our compliance team is available to answer questions about HIPAA requirements and how CrownDesk supports your compliance efforts. Contact us at hello@xaltrax.com for assistance.
Get Your BAA
Business Associate Agreements are automatically provided to all CrownDesk healthcare customers. Contact us if you need a signed copy for your records.
XaltraX Inc.
Email: hello@xaltrax.com
Phone: (302) 861-2222
Address: 254 Chapman Rd, Ste 208 #24467, Newark, Delaware 19702 US
We respond to compliance inquiries within 2 business days.