HIPAA Compliance Statement for Mendlist.com
Last Updated: 12-07-2024
At Mendlist.com, we are committed to protecting the privacy and security of your personal health information (PHI) in compliance with the Health Insurance Portability and Accountability Act (HIPAA). This statement outlines how we meet HIPAA requirements to ensure the confidentiality, integrity, and availability of your sensitive data.
1. Our Commitment to Your Privacy
Mendlist.com prioritizes your privacy and follows all applicable HIPAA regulations to safeguard your PHI. We implement stringent administrative, technical, and physical safeguards to protect your data from unauthorized access, use, or disclosure.
2. How We Protect Your PHI
To ensure the security of your PHI, Mendlist.com has implemented the following measures:
Technical Safeguards
- Encryption: All data, including PHI, is encrypted in transit using HTTPS and TLS protocols and at rest using advanced encryption standards.
- Access Control: Only authorized provider have access to your PHI, and access is based on the services you’ve received.
- Automatic Logout: Sessions automatically log out after 5 minutes of inactivity to prevent unauthorized access.
- Audit Logs: We track and log all access to PHI to monitor for unauthorized activity.
Administrative Safeguards
- Staff Training: All employees and contractors are trained on HIPAA compliance and are required to follow strict privacy and security policies.
- Business Associate Agreements (BAAs): We ensure that all third-party vendors and partners with access to PHI sign BAAs and comply with HIPAA regulations.
Physical Safeguards
- Data Center Security: We use HIPAA-compliant hosting providers with secure data centers protected by advanced physical security measures.
- Device Security: All devices used to access PHI are protected by encryption, secure passwords, and role-based access controls.
3. Data Use and Sharing
We only use your PHI to:
- Provide and improve holistic provider services.
- Facilitate communication between clients and provider.
- Maintain accurate records of your services.
We do not sell or share your PHI with any third parties unless required by law or with your explicit consent.
4. Data Backup and Recovery
- Weekly Backups: PHI is backed up weekly to ensure its availability in case of system failures.
- Disaster Recovery Plan: In the event of a breach or unauthorized access:
- We will secure affected systems immediately.
- Notify affected clients and providers promptly, including any necessary steps to mitigate risks.
- Report the incident to the Department of Health and Human Services (HHS) if required.
5. Your Rights Under HIPAA
As a user of Mendlist.com, you have the following rights regarding your PHI:
- Access: You may request a copy of your PHI at any time.
- Amendments: You may request corrections to your PHI if it is inaccurate or incomplete.
- Accounting of Disclosures: You have the right to request a report of how your PHI has been shared.
- Restrictions: You may request limitations on how your PHI is used or shared.
- Confidential Communications: You can request that we communicate with you in specific ways (e.g., via email or phone).
6. Contact Information
If you have any questions about our HIPAA compliance practices or your rights, please contact us:
- Phone: 317-426-6499
- Email: compliance@mendlist.com
- Mailing Address: 1035 Port Orange Ct, Naples, FL 34120
7. Changes to This Statement
We may update this HIPAA Compliance Statement as necessary to stay compliant with legal and industry standards. Updates will be posted on this page with the revised date.
By using Mendlist.com, you acknowledge our commitment to HIPAA compliance and the protection of your PHI.
Thank you for trusting us with your sensitive information.
