Compliance

HIPAA Compliance

Protecting patient health information is at the core of every healthcare program we run. Our people, processes and technology are built HIPAA-first so you can trust us with your most sensitive data.

How We Protect Data

Built HIPAA-first across people, process & technology

Trained & Certified Staff

Every agent handling protected health information is trained on HIPAA requirements and regularly re-certified.

Secure Technology

We use secure messaging, encrypted storage and audit trails to protect data at rest and in transit.

Strict Access Controls

Access to PHI is limited to authorized personnel on a need-to-know basis, with full logging.

Ongoing Audits

Regular internal audits and monitoring ensure continued compliance across all healthcare programs.

100% HIPAA Compliant

With a medical answering service compliant for HIPAA, you can always be assured that the data of your patients is 100 percent safe at all times. It protects you and your practice, clinic and hospital from the effects of non-compliance.

Official Policy

HIPAA Privacy Policy

Our full policy governing the privacy and security of Protected Health Information (PHI).

1.0

Scope

This policy outlines the responsibilities of Mid Atlantic Business Management Inc. (“Contractor”) to safeguard the privacy and security of Protected Health Information (“PHI”) in compliance with the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), including the HIPAA Privacy Rule and Security Rule (45 CFR Parts 160 and 164), as well as the Health Information Technology for Economic and Clinical Health (HITECH) Act.

This policy operates in conjunction with the Business Associate Agreement (“BAA”) executed between Mid Atlantic Business Management Inc. and each Client.

Definitions:

  • Client: Any customer with whom Mid Atlantic Business Management Inc. has a legal Business Associate Agreement.
  • Served Patients: Patients who receive services from or through the Contractor.
  • Contractor: Mid Atlantic Business Management Inc.
2.0

Scope

This policy applies to all Clients, Served Patients, and Contractor workforce members who access PHI. The Contractor's workforce includes employees, volunteers, trainees, subcontractors, and any person under direct control of the Contractor, regardless of compensation status.

3.0

Roles and Responsibilities

3.1 Privacy Officer

Andy Gawai, Director of Client Relations, is designated as the Privacy Officer and will:

  • Develop and implement policies and procedures regarding the use and disclosure of PHI;
  • Monitor compliance with HIPAA regulations and this Privacy Policy;
  • Ensure BAAs are in place and enforced with Clients and subcontractors;
  • Serve as the primary contact for privacy inquiries and complaints.
Privacy Officer — Contact Information
Justin Keishing
705-14 Keystone Park Drive, Morrisville NC, 27560 USA

3.2 Workforce Training

All workforce members who handle PHI must complete HIPAA training tailored to their job responsibilities. Training will be documented and retained for a minimum of six (6) years.

3.3 Safeguards

The Contractor will implement administrative, technical, and physical safeguards, including:

  • Administrative: Written policies on PHI handling and disclosure;
  • Technical: Role-based access control and audit trails for PHI systems;
  • Physical: Secured workspaces, locked storage, and access-restricted areas.
4.0

Complaints Process

Individuals may file complaints related to PHI privacy:

  • All complaints must be submitted to the Privacy Officer;
  • The Privacy Officer will maintain documentation of all complaints and resolution steps;
  • Complaint procedures are available upon request.
5.0

Breach Notification

In accordance with 45 CFR §§ 164.400-414, the Contractor will notify the Client of any unauthorized access, use, or disclosure of unsecured PHI within 10 business days of discovery. Breach notifications will include:

  • A description of the breach;
  • Types of information involved;
  • Steps taken to mitigate harm;
  • Contact procedures for affected individuals.
6.0

Disciplinary Actions

Violations of this policy may result in disciplinary action, up to and including suspension or termination. Sanctions will align with the Contractor's internal disciplinary procedures.

7.0

Use and Disclosure of PHI

The Contractor and its workforce will:

  • Use and disclose PHI only as permitted under HIPAA or with valid authorization;
  • Comply with the “minimum necessary” standard by limiting PHI access to only what is required;
  • Adhere to any signed participant authorization per 45 CFR §164.508.
8.0

Definitions and Standards

8.1 Use vs. Disclosure

  • Use: Internal utilization of PHI by workforce members within their roles.
  • Disclosure: Sharing PHI with individuals or entities outside the Contractor, unless permitted under HIPAA.

8.2 Minimum Necessary and Limited Data Sets

PHI use/disclosure will be minimized. Limited Data Sets exclude the following identifiers:

  • Names, full postal addresses, SSNs, phone numbers, email addresses;
  • Medical record numbers, account numbers, and license numbers;
  • IP addresses, URLs, biometric identifiers, and photographic images.

8.3 PHI Definition

PHI is any health-related information that identifies or could reasonably be used to identify an individual. This includes data relating to treatment, payment, or healthcare operations for living or deceased individuals.

9.0

Non-Retaliation

Contractor prohibits retaliation against any individual who:

  • Files a privacy complaint;
  • Participates in a privacy investigation;
  • Exercises any HIPAA-related rights.

No individual may be required to waive HIPAA rights as a condition of service.

10.0

Subcontractor Compliance

Subcontractors and vendors who access PHI must:

  • Sign a HIPAA-compliant agreement;
  • Implement safeguards in line with this policy;
  • Notify the Contractor of any PHI breach.
11.0

Policy Management

This Privacy Policy is subject to change. The Contractor may amend or revise this document at any time, and Clients will be notified of significant updates.

12.0

Contact

Privacy Officer Contact:

Privacy Officer — Contact Information
Justin Keishing
705-14 Keystone Park Drive, Morrisville NC, 27560 USA

Ready for a compliant healthcare answering partner?

Give us 30 days. Fill in the inquiry form and our Client Engagement Team will contact you within 24 hours.

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting, your data will be aggregated with all other user data.