Healthcare Compliance

HIPAA Compliance

CrownDesk is designed from the ground up to meet HIPAA requirements, ensuring your patient data remains secure and compliant.

HIPAA Compliant

Certified Business Associate

BAA Included

Automatic Agreement

PHI Protected

End-to-End Security

What is HIPAA?

The Health Insurance Portability and Accountability Act (HIPAA) is a federal law that requires the protection and confidential handling of protected health information (PHI). HIPAA applies to covered entities and their business associates.

Key HIPAA Requirements

  • Privacy Rule: Protects individual health information held by covered entities
  • Security Rule: Sets standards for protecting electronic PHI (ePHI)
  • Breach Notification Rule: Requires notification of PHI breaches
  • Omnibus Rule: Strengthens patient privacy protections

Who Must Comply?

Covered Entities

  • • Healthcare providers
  • • Health plans
  • • Healthcare clearinghouses

Business Associates

  • • Technology vendors
  • • Billing companies
  • • Cloud service providers

CrownDesk HIPAA Compliance

Business Associate Agreement (BAA)

CrownDesk signs a Business Associate Agreement with all healthcare customers automatically upon subscription. This agreement outlines our responsibilities for protecting PHI and our compliance with HIPAA requirements.

PHI Handling Safeguards

Administrative Safeguards

Security officer designation, workforce training, access management

Physical Safeguards

Facility access controls, workstation security, device/media controls

Technical Safeguards

Access control, audit controls, integrity, transmission security

Minimum Necessary Standard

CrownDesk implements role-based access controls ensuring users only access the minimum PHI necessary to perform their job functions. This includes granular permissions and audit trails for all data access.

Technical Security Measures

Encryption Requirements

Data in Transit

  • • TLS 1.3 encryption for all communications
  • • Perfect Forward Secrecy implementation
  • • Certificate pinning and validation

Data at Rest

  • • AES-256 encryption for all stored PHI
  • • Database-level encryption
  • • Encrypted backup storage

Access Controls

  • • Unique user identification for each person accessing PHI
  • • Role-based access control with principle of least privilege
  • • Multi-factor authentication required for all users
  • • Automatic logoff after period of inactivity
  • • Encryption and decryption controls

Audit Controls

  • • Comprehensive audit logs for all PHI access
  • • Immutable audit trail storage
  • • Real-time monitoring and alerting
  • • Regular audit log review and analysis

Your HIPAA Responsibilities

As a Covered Entity

  • • Ensure all workforce members are trained on HIPAA requirements
  • • Implement and maintain required administrative, physical, and technical safeguards
  • • Designate a HIPAA Security Officer and Privacy Officer
  • • Conduct periodic security assessments
  • • Have an incident response plan for potential breaches

Using CrownDesk Compliantly

  • • Use strong, unique passwords and enable multi-factor authentication
  • • Log out of the system when not in use
  • • Do not share login credentials with other users
  • • Report any suspected security incidents immediately
  • • Only access PHI when necessary for your job duties

Patient Rights

  • • Right to access their PHI
  • • Right to request amendments to their PHI
  • • Right to an accounting of PHI disclosures
  • • Right to request restrictions on use/disclosure
  • • Right to request confidential communications

Breach Response

What Constitutes a Breach?

A breach is the acquisition, access, use, or disclosure of PHI in a manner not permitted under the Privacy Rule that compromises the security or privacy of the PHI.

CrownDesk Breach Response

  • • Immediate containment and assessment of the incident
  • • Investigation to determine scope and cause
  • • Notification to affected customers within 24 hours
  • • Assistance with breach notification requirements
  • • Implementation of corrective measures

Your Breach Notification Requirements

  • • Notify individuals within 60 days
  • • Notify HHS within 60 days
  • • Notify media if breach affects 500+ individuals
  • • Maintain documentation of all breaches

Compliance Resources

Training and Education

  • • HIPAA compliance training for your staff
  • • Regular security awareness updates
  • • Best practices documentation
  • • Compliance webinars and workshops

Documentation

  • • Business Associate Agreement template
  • • Security policies and procedures
  • • Risk assessment templates
  • • Incident response planning guides

Support

Our compliance team is available to answer questions about HIPAA requirements and how CrownDesk supports your compliance efforts. Contact us at hello@xaltrax.com for assistance.

Get Your BAA

Business Associate Agreements are automatically provided to all CrownDesk healthcare customers. Contact us if you need a signed copy for your records.

XaltraX Inc.

Email: hello@xaltrax.com

Phone: (302) 861-2222

Address: 254 Chapman Rd, Ste 208 #24467, Newark, Delaware 19702 US

We respond to compliance inquiries within 2 business days.