HIPAA Compliance
How SHEALTH.AI protects Protected Health Information (PHI)
1. What Is HIPAA and Who It Applies To
HIPAA was enacted in 1996 and sets the standard for protecting sensitive patient data in the United States. It applies to Covered Entities (hospitals, clinics, health plans, healthcare clearinghouses) and their Business Associates — vendors and service providers who handle PHI on their behalf.
SHEALTH.AI operates as a Business Associate to the healthcare organizations (Covered Entities) that use the platform. This means we are contractually and legally bound by HIPAA requirements whenever we process, store, or transmit PHI on your behalf.
2. Business Associate Agreement (BAA)
A Business Associate Agreement is a legally required contract between a Covered Entity and a Business Associate. It specifies how PHI may be used, the safeguards the Business Associate must maintain, and the obligations in the event of a breach.
SHEALTH.AI provides a signed BAA to all healthcare organization customers prior to processing any PHI. The BAA covers:
- Permitted uses and disclosures of PHI
- Minimum necessary standards for PHI access
- Obligations to safeguard PHI using administrative, physical, and technical controls
- Breach notification timelines (within 60 days of discovery)
- Return or destruction of PHI upon contract termination
3. Technical Safeguards
SHEALTH.AI implements the technical safeguards required under the HIPAA Security Rule (45 CFR § 164.312):
- Encryption: All PHI is encrypted in transit using TLS 1.2+ and at rest using AES-256
- Access controls: Unique user identification, role-based permissions, and automatic session timeouts
- Audit controls: Immutable logs record every access, modification, transmission, and deletion of PHI
- Integrity controls: Checksums and validation mechanisms ensure PHI is not improperly altered or destroyed
- Transmission security: DICOMweb communications are secured and authenticated end-to-end
4. Administrative Safeguards
Beyond technical controls, SHEALTH.AI maintains the administrative safeguards required under 45 CFR § 164.308:
- A designated Privacy and Security Officer responsible for HIPAA compliance
- Regular workforce training on HIPAA obligations and PHI handling procedures
- Formal risk analysis and risk management processes conducted at least annually
- Contingency planning including data backup, disaster recovery, and emergency access procedures
- Vendor management policies ensuring all sub-processors handling PHI sign appropriate data protection agreements
5. Patient Rights Under HIPAA
HIPAA grants patients specific rights over their health information. SHEALTH.AI is built to support Covered Entities in fulfilling these obligations:
- Right of Access: Patients may request copies of their PHI held by the Covered Entity
- Right to Amend: Patients may request corrections to inaccurate or incomplete health records
- Right to an Accounting of Disclosures: Patients can request a log of certain disclosures of their PHI
- Right to Restrict: Patients may ask the Covered Entity to limit how their PHI is used or disclosed
Requests related to patient rights should be directed to your healthcare provider (the Covered Entity), not to SHEALTH.AI directly. We will support the Covered Entity in fulfilling such requests within the timelines required by law.
6. Breach Notification
In the event of a security incident involving PHI, SHEALTH.AI follows the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414):
- SHEALTH.AI will notify the affected Covered Entity without unreasonable delay and no later than 60 calendar days after discovery of a breach
- Notification will include the nature of the breach, PHI involved, steps taken to mitigate harm, and recommended actions for the Covered Entity
- The Covered Entity is responsible for notifying affected patients and, where required, the U.S. Department of Health and Human Services (HHS)
7. De-identification of PHI
Where SHEALTH.AI uses health data for product improvement, AI model development, or research, it does so exclusively with data that has been de-identified in accordance with HIPAA's Safe Harbor method or Expert Determination method as set out in 45 CFR § 164.514(b).
De-identified data is not considered PHI under HIPAA and therefore is not subject to the Privacy Rule. SHEALTH.AI maintains strict technical and operational controls to ensure that de-identified data cannot be re-linked to any individual patient.
HIPAA Questions or BAA Requests
To request a Business Associate Agreement, report a potential breach, or ask questions about our HIPAA compliance programme, contact your SHEALTH.AI account representative or reach our Privacy Officer at hipaa@shealth.ai.