Last Updated: Nov 2024
React Strategies LLC ("we," "us," "our") is committed to ensuring that ReactEHR.com ("Platform") complies with the Health Insurance Portability and Accountability Act of 1996 (HIPAA) and the associated Health Information Technology for Economic and Clinical Health (HITECH) Act. We recognize the importance of protecting the privacy and security of health information and are dedicated to safeguarding all Protected Health Information (PHI) within our systems.
This HIPAA Compliance Statement outlines the measures we take to adhere to HIPAA standards, ensuring the confidentiality, integrity, and availability of PHI for our users and their patients.
Risk Analysis and Management: We regularly assess risks and vulnerabilities that may impact the confidentiality, integrity, and security of PHI within our Platform and mitigate identified risks.
Employee Training and Awareness: All employees handling PHI receive HIPAA compliance training, including policies for protecting PHI and reporting any security incidents.
Access Control Policies: Access to PHI is strictly limited to authorized personnel only, and we enforce role-based access to ensure that users only have access to information necessary for their role.
Business Associate Agreements (BAAs): We enter into BAAs with any third-party vendors who may have access to PHI, ensuring that they meet HIPAA standards for data protection and confidentiality.
Data Center Security: Our data centers use physical security measures, such as surveillance, restricted access, and monitoring systems, to prevent unauthorized access to servers storing PHI.
Workstation Security: Employee workstations that may have access to PHI are protected with appropriate security measures, including access controls, device monitoring, and secure configurations.
Data Encryption: PHI is encrypted both in transit (using TLS/SSL) and at rest (using AES-256 encryption) to prevent unauthorized access and ensure data security.
Access Controls: We use robust access controls, including multi-factor authentication, to restrict access to PHI and monitor user activities within the Platform.
Automatic Logoff: Our Platform is designed to log users out after a period of inactivity to prevent unauthorized access to PHI.
Audit and Monitoring: We continuously monitor and log access to PHI to detect any unauthorized activity. Regular audits are conducted to review access logs and ensure compliance with security policies.
Incident Response Plan: React Strategies LLC has a formal Incident Response Plan in place to quickly address and respond to any data breaches or security incidents that may impact PHI.
Breach Notification: In the event of a breach involving PHI, we will notify affected users and comply with all HIPAA breach notification requirements, including reporting to the Department of Health and Human Services (HHS) as applicable.
While we implement extensive safeguards to protect PHI, we remind users of the importance of following security best practices when accessing and using the Platform. This includes protecting login credentials, promptly reporting any security incidents, and ensuring that access to PHI is restricted to authorized personnel only.
React Strategies LLC regularly reviews and updates its HIPAA compliance policies and procedures to ensure continued adherence to HIPAA standards. Periodic audits are conducted to assess the effectiveness of our security measures and to address any areas for improvement.
If you have any questions about our HIPAA compliance practices or this statement, please contact us.
End of HIPAA Compliance Statement